VISAM VBASE Editor version 11.5.0.2 and VBASE Web-Remote Module may allow weak or insecure permissions on the VBASE directory resulting in elevation of privileges or malicious effects on the system the next time a privileged user runs the application.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-084-01 | us government resource third party advisory mitigation |