Description
Director Agent 6.1 before 6.1.2.3 in IBM Systems Director on AIX and Linux uses incorrect permissions for the (1) diruninstall and (2) opt/ibm/director/bin/wcitinst scripts, which allows local users to gain privileges by executing these scripts.
Affected products
- ibm / director_agent6.1 – 6.1
- ibm / director_agent6.1.2 – 6.1.2
References
- MISChttp://www.securityfocus.com/bid/39305
- VENDOR_ADVISORYhttp://secunia.com/advisories/39194
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/57611
- MISChttp://www.securitytracker.com/id?1023831
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2010/0830
- MISChttp://www-01.ibm.com/support/docview.wss?uid=isg1PM08236
- MISChttp://osvdb.org/63595