Overview
A vulnerability exists in Sun StorEdge Enterprise Storage Manager (ESM) that may allow unauthorized local users to gain root privileges.
Description
The Sun StorEdge Enterprise Storage Manager (ESM) version 2.1 for the Sun SPARC platform may allow non-root local users assigned the "EMSUser" role to gain root privileges on a StorEdge management station. |
Impact
This vulnerability may allow local users to gain unauthorized root access to the system. |
Solution
Sun released a patch labeled 117367-01 to address this issue. |
Remove the "ESMUser" role from all non-root or untrusted users on the management station. |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was publicly reported by Sun Alert Notification.
This document was written by Jeff Gennari.
Other Information
CVE IDs: | None |
Severity Metric: | 2.03 |
Date Public: | 2004-06-21 |
Date First Published: | 2004-09-03 |
Date Last Updated: | 2004-09-08 20:43 UTC |
Document Revision: | 73 |