Incorrect default permissions in Apache Groovy - CVE-2020-17521

 

Incorrect default permissions in Apache Groovy - CVE-2020-17521

Published: December 6, 2020


Vulnerability identifier: #VU48792
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-17521
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect default permissions for temporary files and folders that are set by the application. A local user with access to the system can view contents of files and directories or modify them.


Affected software

Apache Groovy
Arch Linux
Oracle Solaris Cluster
Oracle Agile PLM MCAD Connector
Oracle Utilities Application Framework
Oracle Hospitality OPERA 5
Oracle Business Process Management Suite
Oracle Retail Bulk Data Integration
Oracle Communications Services Gatekeeper
Oracle iLearning
Oracle Agile Engineering Data Management
Oracle Data Integrator
Oracle Retail Store Inventory Management
Oracle Retail Service Backbone
MobileFirst Platform
Oracle Communications Evolved Communications Application Server
Oracle WebLogic Server
Primavera Gateway
Fuse
Oracle Communications Diameter Signaling Router
Oracle Identity Manager Connector
Oracle Enterprise Data Quality
IBM Spectrum Control
IBM Cloud Application Performance Management (APM)
Oracle Agile PLM Framework
Oracle Communications BRM - Elastic Charging Engine
Oracle Retail Financial Integration
Oracle Retail Merchandising System
Oracle Retail Integration Bus
Primavera Unifier
Splunk AppDynamics Analytics Agent
RSA Authentication Manager

How to mitigate CVE-2020-17521

Install updates from vendor's website.

Apache Groovy - addressed in versions 2.4.21, 2.5.14, 3.0.7, 4.0.0.ALPHA.2
IBM Spectrum Control - update to 5.4.10
Fuse - update to 7.10.0
MobileFirst Platform - update to 8.0.0.0-MFPF-IF202301121031
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.20
RSA Authentication Manager - update to 8.7 Patch 2
Splunk AppDynamics Analytics Agent - update to 26.1.0

External References

Related Security Bulletins