CVE-2000-1239 describes a critical vulnerability in the HTTP interface of Tivoli Lightweight Client Framework (LCF) within IBM Tivoli Management Framework 3.7.1. An installation misconfiguration sets http_disable to zero, enabling remote authenticated users to bypass file permissions on sensitive Tivoli Endpoint Configuration data files through unspecified log file manipulation. This vulnerability carries a high CVSS score of 9.0, indicating a network-based attack with low complexity, requiring authentication, and leading to complete compromise of confidentiality, integrity, and availability. Despite its severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or community discussion, suggesting it is not currently a widespread threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.7.1CPE matchmatch criteria | cpe:2.3:a:ibm:tivoli_management_framework:3.7.1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.