Security breach when using Campaign with impersonation on RHEL3

Problem or error: You can configure Campaign so that each flowchart opens and executes with the specific operating system permissions of the individual currently running the flowchart, rather than of the user who started the Campaign listener. On Red Hat Enterprise Linux version 3 only, if the Campaign listener is run as root, there is a defect in the operating system calls that Campaign employs to perform this impersonation step. Consequently, each flowchart opens and executes as the root user, with root permissions, rather than as the appropriate individual user, with that user’s permissions. This issue is a defect in RHEL3 and impacts any version of Campaign deployed on that platform.

Solution: This issue has been corrected in RHEL4. If this is an issue in your installation, please contact Unica Technical support for more information.



IBM Unica Campaign
 
8.5.0
For more information, see our support and community site: Customer Central