Inspur ClusterEngine
cpe:2.3:a:inspur:clusterengine:*:*:*:*:*:*:*
- 4.0
A privilege escalation vulnerability has been identified in Inspur ClusterEngine version 4.0. This issue arises from an improper SUID configuration in the component '/opt/tsce4/torque6/bin/getJobsByShell', allowing non-administrative users to gain root access by exploiting the SUID mechanism. The vulnerability enables these users to execute arbitrary commands with elevated privileges.
Exploitation of this vulnerability allows non-administrative users to gain root access on the affected system.
To reproduce this vulnerability, a non-administrative user can execute the 'getJobsByShell' component with a command shell as an argument. This will trigger the SUID privilege escalation, resulting in root access.
Users are advised to upgrade the relevant components to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.