7.2

CVE-2004-1054

Untrusted execution path vulnerability in invscout in IBM AIX 5.1.0, 5.2.0, and 5.3.0 allows local users to gain privileges by modifying the PATH environment variable to point to a malicious "uname" program, which is executed from lsvpd after lsvpd has been invoked by invscout.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Aix Version 5.1
Ibm ≫ Aix Version 5.1l
Ibm ≫ Aix Version 5.2
Ibm ≫ Aix Version 5.2.2
Ibm ≫ Aix Version 5.2_l
Ibm ≫ Aix Version 5.3
Ibm ≫ Aix Version 5.3_l
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.95% 0.566
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www-1.ibm.com/support/search.wss?rs=0&q=IY64820&apar=only
http://www-1.ibm.com/support/search.wss?rs=0&q=IY64852&apar=only
http://www-1.ibm.com/support/search.wss?rs=0&q=IY64976&apar=only
http://www.idefense.com/application/poi/display?id=171&type=vulnerabilities
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/18619