CVE-2008-5417
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
10/12/2008
Last modified:
09/04/2025
Description
HP DECnet-Plus 8.3 before ECO03 for OpenVMS on the Alpha platform uses world-writable permissions for the OSIT$NAMES logical name table, which allows local users to bypass intended access restrictions and modify this table via the (1) SYS$CRELNM and (2) SYS$DELLNM system services.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:hp:decnet_plus_for_openvms:8.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:hp:openvms:8.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page