MEDIUM · 4.6

CVE-2003-0579

uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by prov...

Vulnerability Description

uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by providing a pathname that is under control of the user.

CVSS Score

4.6

MEDIUM

AV:L/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
IbmU2 Universe<= 10.0.0.9

References

FAQ

What is CVE-2003-0579?

CVE-2003-0579 is a vulnerability with a CVSS score of 4.6 (MEDIUM). uvadmsh in IBM U2 UniVerse 10.0.0.9 and earlier trusts the user-supplied -uv.install command line option to find and execute the uv.install program, which allows local users to gain privileges by prov...

How severe is CVE-2003-0579?

CVE-2003-0579 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2003-0579?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm U2 Universe.