| CVE ID | |
| CVSS SCORE | 7.1, AV:N/AC:M/Au:N/C:N/I:N/A:C |
| AFFECTED VENDORS |
Borland |
| AFFECTED PRODUCTS |
AccuRev |
| VULNERABILITY DETAILS |
The specific flaw exists within the diagonostic_doit command of the AccuRev Reprise License Manager service. The issue lies in the handling of paths by the 'outputfile' function. An attacker could leverage this vulnerability to overwrite arbitrary files with diagnostic information under the context of SYSTEM. |
| ADDITIONAL DETAILS |
07/09/2015 - ZDI emailed vendor and requested contact -- Mitigation:
|
| DISCLOSURE TIMELINE |
|
| CREDIT | rgod |