V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2008-0890
CVE
High

Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and…

CVSS
7.2
High
EPSS
0.00
p29
Published
2008-01-01
Updated
2008-01-01
Description

Red Hat Directory Server 7.1 before SP4 uses insecure permissions for certain directories, which allows local users to modify JAR files and execute arbitrary code via unknown vectors.

Tags · CWE
LPE
CWE-264
CWE-732
CAPEC-1
CAPEC-17
CAPEC-60
CAPEC-61
CAPEC-62
CAPEC-122
CAPEC-127
CAPEC-180
CAPEC-206
CAPEC-234
CAPEC-642
Affected products
Directory_server ≤ 7.1
CVSS vector
AV:L/AC:L/Au:N/C:C/I:C/A:C
Timeline
2008-01-01
Published
2008-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Authentication
Au: N
None (N)
Confidentiality Impact
C: C
Complete
Integrity Impact
I: C
Complete
Availability Impact
A: C
Complete
Exploit indicators
EPSS
0.004 · p29
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-127 · CWE-732
└ via CAPEC-60 · CWE-732
└ via CAPEC-642 · CWE-732
└ via CAPEC-122 · CWE-732
└ via CAPEC-60 · CWE-732
└ via CAPEC-206 · CWE-732
└ via CAPEC-642 · CWE-732
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
redhat-dsTracked
redhat-dsTracked
directory_server*Tracked
Source databases
CVE
RED