Directory Permissions Flaw in Oracle Internet Directory 2.1.1.1
CVE-2001-0300

Currently unrated

Key Information:

Vendor

Oracle

Vendor
CVE Published:
2 June 2001

What is CVE-2001-0300?

The Oracle Internet Directory version 2.1.1.1 is affected by a vulnerability due to world-writable permissions on its log file directory (ldaplog). This misconfiguration may enable local users to exploit the system by deleting logs or overwriting files through symlink attacks, posing a significant risk to data integrity and security. Proper permission settings are essential to safeguard against unauthorized file manipulation.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.