Local Privilege Escalation Vulnerability in IBM Platform and Spectrum LSF
CVE-2020-4278
7.4HIGH
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 5 March 2020
Summary
The vulnerability arises from improper file permissions in IBM Platform LSF and IBM Spectrum LSF products. When specific debug settings are activated in a Linux or Unix environment, a local user can exploit these weak permissions to elevate their access privileges, potentially impacting system integrity and security. For more insights, consult IBM's support pages and their vulnerability disclosure information.
Affected Version(s)
Spectrum Computing Suite for High Performance Analytics 10.2
Spectrum LSF 10.1
Spectrum LSF 9.1
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved