Local User Job Manipulation in IBM Spectrum LSF
CVE-2018-1724
5.9MEDIUM
What is CVE-2018-1724?
A vulnerability in IBM Spectrum LSF allows local users to alter their job user during submission due to inadequate file permission configurations. This can lead to unintended privilege escalation, enabling users to execute jobs under different user accounts. Organizations should assess their deployments of IBM Spectrum LSF versions 9.1.1, 9.1.2, 9.1.3, and 10.1 to ensure proper security measures are in place.
Affected Version(s)
Spectrum LSF 10.1
Spectrum LSF 9.1.1
Spectrum LSF 9.1.2