← Back

CVE-2012-4845

nvd nist
Published: Oct 20, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:L/Au:S/C:C/I:N/A:N
Exploitability: 8.0 / Impact: 6.9
Source: NVD

Description

The FTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.1.4-FP-25 SP-02, does not properly manage privileges in an RBAC environment, which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.

Affected (3)

Products: Ibm: Aix, Vios
2 products
Aix
Vios
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 6.1
Version 7.1
Version 2.2.1.4 fp-25_sp-02

Related CWEs

References (16)

Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.