CVE-2016-7490

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
10/11/2016
Last modified:
12/04/2025

Description

The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and possibly clobber system files or perhaps elevate privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:teradata:studio_express:15.12.00.00:*:*:*:*:*:*:*