Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
SSH Tectia Server for IBM z/OS before 5.4.0 uses insecure world-writable permissions for (1) the server pid file, which allows local users to cause arbitrary processes to be stopped, or (2) when _BPX_BATCH_UMASK is missing from the environment, creates HFS files with insecure permissions, which allows local users to read or modify these files and have other unknown impact.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
SSH Tectia Server for IBM z/OS本地权限提升漏洞
Vulnerability Description
SSH Tectia客户端/服务器解决方案是基于Secure Shell技术的多平台点到点通讯安全解决方案,SSH Tectia Server for IBM z/OS是其中的一个产品模块。 SSH Tectia Server安装文件时设置了不安全的访问权限,本地攻击者可能利用此漏洞提升自己的权限。 SSH Tectia Server for IBM z/OS以完全可写的权限创建文件和目录,因此本地用户可以删除、控制或替换某些文件,获得权限提升。
CVSS Information
N/A
Vulnerability Type
N/A