CVE-2014-3020: IBM Embedded WebSphere Application Server

Medium severity, CVSS 6.9. EPSS: 0.3% chance of exploitation in the next 30 days.

install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.

Affected products

  • IBM Embedded WebSphere Application Server: version 7.0 only
  • IBM Tivoli Integrated Portal: version 2.1 only; version 2.2 only

Published 2014-07-29. Last modified 2026-06-17.