Vulnerabilities > CVE-2001-0208 - Unspecified vulnerability in Microfocus Cobol 4.1

047910
CVSS 4.6 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
low complexity
microfocus
exploit available

Summary

MicroFocus Cobol 4.1, with the AppTrack feature enabled, installs the mfaslmf directory and the nolicense file with insecure permissions, which allows local users to gain privileges by modifying files.

Vulnerable Configurations

Part Description Count
Application
Microfocus
1

Exploit-Db

descriptionMicro Focus Cobol 4.1 Arbitrary Command Execution Vulnerability. CVE-2001-0208 . Local exploit for unix platform
idEDB-ID:20621
last seen2016-02-02
modified2001-02-12
published2001-02-12
reporterDixie Flatline
sourcehttps://www.exploit-db.com/download/20621/
titleMicro Focus Cobol 4.1 - Arbitrary Command Execution Vulnerability