CVE-2015-7442: IBM Installation Manager
High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.
consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value.
Affected products
- IBM Installation Manager: version 1.7.4.3 only; version 1.8.0.0 only; version 1.8.1.0 only; version 1.8.2.0 only; version 1.8.2.1 only; version 1.8.3.0 only
- IBM Packaging Utility: up to and including 1.7.4.3; version 1.8.0.0 only; version 1.8.1.0 only; version 1.8.2.0 only; version 1.8.2.1 only; version 1.8.3.0 only
Published 2016-01-02. Last modified 2026-06-17.