Executive Summary

Informations
Name CVE-1999-0338 First vendor Publication 1994-02-24
Vendor Cve Last vendor Modification 2022-08-17

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:C/I:C/A:C)
Cvss Base Score 7.2 Attack Range Local
Cvss Impact Score 10 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

AIX Licensed Program Product performance tools allow local users to gain root access.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-1999-0338

CPE : Common Platform Enumeration

TypeDescriptionCount
Os 2

Open Source Vulnerability Database (OSVDB)

Id Description
17082 IBM AIX Performance Tools tprof -x Parameter Privilege Escalation

AIX Performance Tools contain a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when the 'tprof' utility is run with the '-x' parameter. Command arguments supplied to this parameter are run with the same privileges as 'tprof' (SUID root by default), allowing arbitrary privileged command execution.
17081 IBM AIX Performance Tools svmon Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'svmon' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17080 IBM AIX Performance Tools stripnm Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'stripnm' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17079 IBM AIX Performance Tools rmss Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'rmss' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17078 IBM AIX Performance Tools rmap Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'rmap' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17077 IBM AIX Performance Tools netpmon Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'netpmon' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17076 IBM AIX Performance Tools lvedit Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'lvedit' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17075 IBM AIX Performance Tools genld Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'genld' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17074 IBM AIX Performance Tools genkld Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'genkld' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17073 IBM AIX Performance Tools genkex Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'genkex' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
17072 IBM AIX Performance Tools fileplace Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'fileplace' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.
7986 IBM AIX Performance Tools filemon Unspecified Local Root Access

AIX Performance Tools contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is due to an unspecified error in "bosext1.extcmds.obj" Licensed Program Product, specifically the 'filemon' utility. This flaw may allow a local attacker to gain root privileges, resulting in a loss of integrity.

Sources (Detail)

Source Url
MISC https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0338

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
Date Informations
2022-08-17 13:27:55
  • Multiple Updates
2021-05-04 12:00:54
  • Multiple Updates
2021-04-22 01:01:07
  • Multiple Updates
2020-05-23 00:14:06
  • Multiple Updates
2013-05-11 11:56:06
  • Multiple Updates