Vulnerability Note VU#976470

Sun Enterprise Storage Manager may allow an unprivileged local user to gain root access

Original Release date: 03 Sep 2004 | Last revised: 08 Sep 2004

Overview

A vulnerability exists in Sun StorEdge Enterprise Storage Manager (ESM) that may allow unauthorized local users to gain root privileges.

Description

The Sun StorEdge Enterprise Storage Manager (ESM) version 2.1 for the Sun SPARC platform may allow non-root local users assigned the "EMSUser" role to gain root privileges on a StorEdge management station.

Impact

This vulnerability may allow local users to gain unauthorized root access to the system.

Solution

Sun released a patch labeled 117367-01 to address this issue.

Remove the "ESMUser" role from all non-root or untrusted users on the management station.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
Sun Microsystems Inc.Affected-03 Sep 2004
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

This vulnerability was publicly reported by Sun Alert Notification.

This document was written by Jeff Gennari.

Other Information

  • CVE IDs: Unknown
  • Date Public: 21 Jun 2004
  • Date First Published: 03 Sep 2004
  • Date Last Updated: 08 Sep 2004
  • Severity Metric: 2.03
  • Document Revision: 73

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.