CVE-2015-7442IBM Packaging Utility vulnerability

CWE-2644 documents4 sources
Severity
7.0HIGHNVD
EPSS
0.1%
top 67.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateMay 17

Description

consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages2 packages

NVDibm/packaging_utility1.7.4.3+5
NVDibm/installation_manager6 versions+5

🔴Vulnerability Details

3
GHSA
GHSA-qp2r-pc98-7q4w: consoleinst2022-05-17
Kernel
namei: allow restricted O_CREAT of FIFOs and regular files2018-08-23
CVEList
CVE-2015-7442: consoleinst2016-01-02
CVE-2015-7442 — IBM Packaging Utility vulnerability | cvebase