Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts, and possibly systems administrator created user accounts, are incorrectly assigned to groups that allow higher system-level privileges than intended for those user accounts. Depending on the usage of these accounts, this may lead to full system compromise.
References
Configurations
No configuration.
History
31 Jan 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-281 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.0 |
Summary |
|
08 Jan 2025, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-01-08 21:15
Updated : 2025-01-31 18:15
NVD link : CVE-2024-52869
Mitre link : CVE-2024-52869
CVE.ORG link : CVE-2024-52869
JSON object : View
Products Affected
No product.
CWE
CWE-281
Improper Preservation of Permissions