Saturday, April 6, 2019

IBM Security Bulletin: IBM Sterling Connect:Direct for UNIX Allows a User with Sudo Access Restricted to Certain Connect:Direct Executable Files to Expand Access Beyond the Restriction (CVE-2018-1903)

UNIX system administrators may grant access to run certain executable files with expanded privilege via the sudo utility. Connect:Direct for UNIX has a vulnerability that could allow a user to escape this sudo executable file restriction and perform unauthorized commands with expanded privilege.

CVE(s): CVE-2018-1903

Affected product(s) and affected version(s):
IBM Sterling Connect:Direct for Unix 6.0.0
IBM Sterling Connect:Direct for Unix 4.3.0
IBM Sterling Connect:Direct for Unix 4.2.0

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://www.ibm.com/support/docview.wss?uid=ibm10875386
X-Force Database: https://exchange.xforce.ibmcloud.com/vulnerabilities/152532

The post IBM Security Bulletin: IBM Sterling Connect:Direct for UNIX Allows a User with Sudo Access Restricted to Certain Connect:Direct Executable Files to Expand Access Beyond the Restriction (CVE-2018-1903) appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team https://ibm.co/2FU2Fq8

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.