CVE-2024-52869 Details
Description
Certain Teradata account-handling code through 2024-11-04, used with SUSE Enterprise Linux Server, mismanages groups. Specifically, when there is an operating system move from SUSE Enterprise Linux Server (SLES) 12 Service Pack (SP) 2 or 3 to SLES 15 SP2 on Teradata Database systems, some service/system user accounts, and possibly systems administrator created user accounts, are incorrectly assigned to groups that allow higher system-level privileges than intended for those user accounts. Depending on the usage of these accounts, this may lead to full system compromise.
A vulnerability exists in Teradata systems running on SUSE Linux Enterprise Server (SLES) 15 SP2, following an upgrade from SLES 12 SP2 or SP3. The issue arises because the migration process does not account for changes in group identifiers made by SUSE, leading to incorrect group assignments for service and system user accounts. This mismanagement can grant users higher privileges than intended, potentially allowing for full system compromise. The vulnerability is particularly severe if a user is assigned to a high-privileged group, such as 'disk', which could be exploited to gain root access.
Teradata recommends that system administrators manually verify all Linux user group assignments after migrating from SLES 12 to 15. For default system and service user accounts, Teradata support personnel should correct any incorrect group assignments. Teradata is also developing a script to identify and fix certain user accounts with incorrect group identifiers in SLES 15 SP2 and above, although no release date has been provided.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 8, 2025CISA-ADP
Assessed Jan 31, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chrismanson.com/CVE/cve-2024-52869.html | [email protected] | AdvisoryExploitRemedy |
| https://www.teradata.com/trust-security-center/data-security | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-281 | Improper Preservation of Permissions | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Teradata SUSE Linux Enterprise Server | 15 SP2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 31, 2025 | CVE Modified | CISA-ADP |
| Jan 8, 2025 | New CVE Received | [email protected] |
Volerion