4.6
CVSSv2

CVE-2001-0208

Published: 02/06/2001 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.

Vulnerable Product Search on Vulmon Subscribe to Product

microfocus cobol 4.1

Exploits

source: wwwsecurityfocuscom/bid/2359/info Micro Focus Cobol is a development suite for unix platforms offered by Merant It is typically licensed on a per-user basis If Micro Focus Cobol is installed with the 'Apptrack' feature enabled, local users may be able to elevate privileges A shell script called 'nolicense' that is executed as ...