File Permission Bypass in IBM Tivoli Management Framework
CVE-2000-1239
Currently unrated
Summary
The Tivoli Lightweight Client Framework (LCF) within IBM Tivoli Management Framework 3.7.1 contains a vulnerability that enables remote authenticated users to bypass established file permissions on sensitive Tivoli Endpoint Configuration data files. This occurs due to the framework's initialization process, which sets the http_disable parameter to zero, inadvertently allowing access through unspecified log file manipulations. Proper steps should be taken to mitigate exposure and to ensure appropriate access controls are enforced.
References
Timeline
Vulnerability Reserved
Vulnerability published