CERT home
vulnerabilities & fixesevaluations & practicesresearch & analysistraining & education
homesearchFAQsite indexcontact
Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information
 

 View Notes By
Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric

Vulnerability Note VU#976470

Sun Enterprise Storage Manager may allow an unprivileged local user to gain root access

Overview

A vulnerability exists in Sun StorEdge Enterprise Storage Manager (ESM) that may allow unauthorized local users to gain root privileges.

I. Description

The Sun StorEdge Enterprise Storage Manager (ESM) version 2.1 for the Sun SPARC platform may allow non-root local users assigned the "EMSUser" role to gain root privileges on a StorEdge management station.

II. Impact

This vulnerability may allow local users to gain unauthorized root access to the system.

III. Solution

Sun released a patch labeled 117367-01 to address this issue.

Remove the "ESMUser" role from all non-root or untrusted users on the management station.

Systems Affected

VendorStatusDate Updated
Sun Microsystems Inc.Vulnerable3-Sep-2004

References


http://sunsolve.sun.com/search/document.do?assetkey=1-26-57581-1
http://www.osvdb.org/displayvuln.php?osvdb_id=7247
http://secunia.com/advisories/11935/
http://sunsolve.sun.com/search/document.do?assetkey=1-21-117367-01-1&searchclause=117367-01

Credit

This vulnerability was publicly reported by Sun Alert Notification.

This document was written by Jeff Gennari.

Other Information

Date Public06/21/2004
Date First Published09/03/2004 01:11:22 PM
Date Last Updated09/08/2004
CERT Advisory 
CVE Name 
Metric2.03
Document Revision73

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

Copyright 2004 Carnegie Mellon University