4.6
CVSSv2

CVE-2020-8025

Published: 07/08/2020 Updated: 12/08/2020
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 9.3 | Impact Score: 6 | Exploitability Score: 2.5
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions before 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions before 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions before 20180125-3.27.1. openSUSE Leap 15.1 permissions versions before 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions before 20200624.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

suse linux enterprise high performance computing 15

suse linux enterprise server 15

suse linux enterprise software development kit 12