ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS commands with administrator privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fsas Technologies
Fsas Technologies eternus Sf Linux Linux linux Microsoft Microsoft windows Server Oracle Oracle solaris Redhat Redhat linux |
|
| Vendors & Products |
Fsas Technologies
Fsas Technologies eternus Sf Linux Linux linux Microsoft Microsoft windows Server Oracle Oracle solaris Redhat Redhat linux |
Mon, 20 Oct 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 20 Oct 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ETERNUS SF provided by Fsas Technologies Inc. contains an incorrect default permissions vulnerability. A low-privileged user with access to the management server may obtain database credentials, potentially allowing execution of OS commands with administrator privileges. | |
| Weaknesses | CWE-276 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2025-10-20T05:32:41.402Z
Updated: 2025-10-20T14:12:31.176Z
Reserved: 2025-10-16T00:39:29.822Z
Link: CVE-2025-62577
Updated: 2025-10-20T14:12:24.289Z
Status : Awaiting Analysis
Published: 2025-10-20T06:15:36.597
Modified: 2025-10-21T19:31:25.450
Link: CVE-2025-62577
No data.