The web server for Network Associates ePolicy Orchestrator Agent 3.5.0 (patch 3) uses insecure permissions for the "Common Framework\Db" folder, which allows local users to read arbitrary files by creating a subfolder in the EPO agent web root directory.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://knowledgemap.nai.com/KanisaSupportSite/search.do?cmd=displayKC&docType=kc&externalId=KBkb42216xml - | |
References | () http://lists.virus.org/full-disclosure-0508/msg00376.html - Exploit, Vendor Advisory | |
References | () http://reedarvin.thearvins.com/20050811-01.html - | |
References | () http://secunia.com/advisories/16410 - | |
References | () http://www.osvdb.org/18735 - | |
References | () http://www.securityfocus.com/bid/14549 - | |
References | () http://www.vupen.com/english/advisories/2005/1402 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/21839 - |
Information
Published : 2005-08-12 04:00
Updated : 2025-04-03 01:03
NVD link : CVE-2005-2554
Mitre link : CVE-2005-2554
CVE.ORG link : CVE-2005-2554
JSON object : View
Products Affected
network_associates
- epolicy_orchestrator_agent
CWE