search menu icon-carat-right cmu-wordmark

CERT Coordination Center


Sun Enterprise Storage Manager may allow an unprivileged local user to gain root access

Vulnerability Note VU#976470

Original Release Date: 2004-09-03 | Last Revised: 2004-09-08

Overview

A vulnerability exists in Sun StorEdge Enterprise Storage Manager (ESM) that may allow unauthorized local users to gain root privileges.

Description

The Sun StorEdge Enterprise Storage Manager (ESM) version 2.1 for the Sun SPARC platform may allow non-root local users assigned the "EMSUser" role to gain root privileges on a StorEdge management station.

Impact

This vulnerability may allow local users to gain unauthorized root access to the system.

Solution

Sun released a patch labeled 117367-01 to address this issue.

Remove the "ESMUser" role from all non-root or untrusted users on the management station.

Vendor Information

976470
Expand all

Sun Microsystems Inc.

Updated:  September 03, 2004

Status

  Vulnerable

Vendor Statement

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The original Sun Alert Notification is available at:

http://sunsolve.sun.com/search/document.do?assetkey=1-26-57581-1

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A

References

Credit

This vulnerability was publicly reported by Sun Alert Notification.

This document was written by Jeff Gennari.

Other Information

CVE IDs: None
Severity Metric: 2.03
Date Public: 2004-06-21
Date First Published: 2004-09-03
Date Last Updated: 2004-09-08 20:43 UTC
Document Revision: 73

Sponsored by the Department of Homeland Security Office of Cybersecurity and Communications.