CVE-2000-1239

IBM Tivoli Management Framework 3.7.1 - Auth Bypass

Title source: llm
STIX 2.1

Description

The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/3927
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17085
Various Sources x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg21082896

Scores

EPSS 0.0208
EPSS Percentile 79.6%

Details

Status published
Products (1)
ibm/tivoli_management_framework 3.7.1
Published Dec 31, 2000
Tracked Since Feb 18, 2026