Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

IBM Websphere Installation Permissions Vulnerability

The IBM Websphere application server, when installed on Solaris (or possibly AIX), will create an deinstallation shellscript which is mode 777 in /usr/bin. The script is called by pkgmgr, which is run by root. This means that an attacker can modify the script and add malicious code to it, leading to a root compromise once it is run. IBM Websphere also installs many of its data files with mode 777 permissions.







 

Privacy Statement
Copyright 2008, SecurityFocus