File Permission Bypass in IBM Tivoli Management Framework
CVE-2000-1239

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
31 December 2000

Summary

The Tivoli Lightweight Client Framework (LCF) within IBM Tivoli Management Framework 3.7.1 contains a vulnerability that enables remote authenticated users to bypass established file permissions on sensitive Tivoli Endpoint Configuration data files. This occurs due to the framework's initialization process, which sets the http_disable parameter to zero, inadvertently allowing access through unspecified log file manipulations. Proper steps should be taken to mitigate exposure and to ensure appropriate access controls are enforced.

References

Timeline

  • Vulnerability Reserved

  • Vulnerability published

.