Vulnerability Note VU#976470
Sun Enterprise Storage Manager may allow an unprivileged local user to gain root access
OverviewA vulnerability exists in Sun StorEdge Enterprise Storage Manager (ESM) that may allow unauthorized local users to gain root privileges.
I. DescriptionThe Sun StorEdge Enterprise Storage Manager (ESM) version 2.1 for the Sun SPARC platform may allow non-root local users assigned the "EMSUser" role to gain root privileges on a StorEdge management station.II. ImpactThis vulnerability may allow local users to gain unauthorized root access to the system.III. SolutionSun released a patch labeled 117367-01 to address this issue.
Remove the "ESMUser" role from all non-root or untrusted users on the management station.
Systems Affected
References
http://sunsolve.sun.com/search/document.do?assetkey=1-26-57581-1
http://www.osvdb.org/displayvuln.php?osvdb_id=7247
http://secunia.com/advisories/11935/
http://sunsolve.sun.com/search/document.do?assetkey=1-21-117367-01-1&searchclause=117367-01
Credit
This vulnerability was publicly reported by Sun Alert Notification.
This document was written by Jeff Gennari.
Other Information
| Date Public | 06/21/2004 |
| Date First Published | 09/03/2004 01:11:22 PM |
| Date Last Updated | 09/08/2004 |
| CERT Advisory | |
| CVE Name | |
| Metric | 2.03 |
| Document Revision | 73 |
If you have feedback, comments, or additional information about this vulnerability, please send us
email.
|