CVE-2000-1202

IBM HTTP Server SSL Module Common - Remote Code Execution via CLASSPATH Manipulation

Title source: llm
STIX 2.1

Description

ikeyman in IBM IBMHSSSB 1.0 sets the CLASSPATH environmental variable to include the user's own CLASSPATH directories before the system's directories, which allows a malicious local user to execute arbitrary code as root via a Trojan horse Ikeyman class.

References (3)

Core 3
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1092
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/4235
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/54073

Scores

EPSS 0.0058
EPSS Percentile 44.1%

Details

Status published
Products (1)
ibm/http_server_ssl_module_common 1.0
Published Aug 31, 2001
Tracked Since Feb 18, 2026