Vulnerability identifier: #VU95286
Vulnerability risk: Low
CVSSv4.0: 4.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID:
CWE-ID:
CWE-276
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
Security Verify Access Docker
Other software /
Other software solutions
Vendor: IBM Corporation
Description
The vulnerability allows a remote user to escalate privileges on the system.
The vulnerability exists due to incorrect default permissions for files and folders that are set by the application. A remote user with access to the system can view contents of files and directories or install malicious packages.
Mitigation
Install updates from vendor's website.
Vulnerable software versions
Security Verify Access Docker : before 10.0.8
External links
https://www.ibm.com/support/pages/node/7158790
https://exchange.xforce.ibmcloud.com/vulnerabilities/261197
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.