Vulnerability Name:

CVE-2002-2265 (CCN-10703)

Assigned:2002-11-13
Published:2002-11-13
Updated:2017-07-29
Summary:Unspecified vulnerability in LDAP Module in System Authentication of Open Source Internet Solutions (OSIS) 5.4 running on Tru64 UNIX 4.0G and 4.0F allows remote attackers to gain access to arbitrary files or gain privileges via unknown attack vectors.
CVSS v3 Severity:7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): Low
CVSS v2 Severity:6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
Vulnerability Type:CWE-264
Vulnerability Consequences:Gain Access
References:Source: HP
Type: UNKNOWN
SSRT2385

Source: MITRE
Type: CNA
CVE-2002-2265

Source: CCN
Type: OSVDB ID: 60147
HP Tru64 Unix Open Source Internet Solutions (OSIS) System Authentication LDAP Module Unspecified Remote Privilege Escalation

Source: BID
Type: Patch
6174

Source: CCN
Type: BID-6174
HP Tru64/TruCluster OSIS V5.4 LDAP Module Unauthorized File Access Vulnerability

Source: XF
Type: UNKNOWN
tru64-osis-ldap-file-access(10703)

Source: XF
Type: UNKNOWN
tru64-osis-ldap-file-access(10703)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:hp:tru64:4.0f:*:*:*:*:*:*:*
  • OR cpe:/o:hp:tru64:4.0g:*:*:*:*:*:*:*
  • AND
  • cpe:/a:open_source_internet_solutions:open_source_internet_solutions:5.4:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:compaq:tru64:4.0f:*:*:*:*:*:*:*
  • OR cpe:/o:compaq:tru64:4.0g:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    hp tru64 4.0f
    hp tru64 4.0g
    open_source_internet_solutions open source internet solutions 5.4
    compaq tru64 4.0f
    compaq tru64 4.0g