IBM Systems Director contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered due to the Common Agent reset_diragent_keys having a permission level of 754, allowing a local user of the 'system' group to bypass certain security restrictions.
Classification
Location:
Local Access Required
Attack Type:
Misconfiguration
Impact:
Loss of Integrity
Solution:
Workaround,
Patch / RCS
Exploit:
Exploit Unknown
Disclosure:
Vendor Verified
Solution
IBM has released a patch to address this vulnerability. Additionally, it is possible to temporarily work around the flaw by implementing the following workaround: The permission of reset_diragent_keys is set to 500.