4.6
CVSSv2

CVE-2003-0579

Published: 18/08/2003 Updated: 18/10/2016
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

uvadmsh in IBM U2 UniVerse 10.0.0.9 and previous versions trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm u2 universe

Exploits

source: wwwsecurityfocuscom/bid/8203/info A vulnerability has been reported in the IBM U2 UniVerse uvadmsh program that could permit the uvadm user to execute arbitrary code with elevated privileges The -uvinstall option of the vulnerable program allows a user to specify an arbitrary path to a file In cases where uvadmsh is installed s ...