CVE-2020-8025
A Incorrect Execution-Assigned Permissions vulnerability in the permissions package of SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 15-LTSS, SUSE Linux Enterprise Server for SAP 15; openSUSE Leap 15.1, openSUSE Tumbleweed sets the permissions for some of the directories of the pcp package to unintended settings. This issue affects: SUSE Linux Enterprise Server 12-SP4 permissions versions prior to 20170707-3.24.1. SUSE Linux Enterprise Server 15-LTSS permissions versions prior to 20180125-3.27.1. SUSE Linux Enterprise Server for SAP 15 permissions versions prior to 20180125-3.27.1. openSUSE Leap 15.1 permissions versions prior to 20181116-lp151.4.24.1. openSUSE Tumbleweed permissions versions prior to 20200624.
- Affected products
- Suse Linux Enterprise Server 12-Sp4, Suse Linux Enterprise Server 15, Suse Linux Enterprise Server For Sap 15, Suse, Opensuse Leap 15.1, Opensuse Tumbleweed
- Suse Linux Enterprise High Performance Computing
- = 15
- Suse Linux Enterprise Server
- = 15
- Suse Linux Enterprise Software Development Kit
- = 12
- Fix
- Available
- CVSS 3.1
- 9.3 CRITICAL
- EPSS
- 0.5% (39th percentile)
- Weakness
- CWE-279
- NVD status
- Modified
- Published
- 2020-08-07
No indexed exploits for CVE-2020-8025 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2020-8025 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.