### [CVE-2018-2025](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2025) ![](https://img.shields.io/static/v1?label=Product&message=Spectrum%20Protect%20Backup-Archive%20Client&color=blue) ![](https://img.shields.io/static/v1?label=Product&message=Spectrum%20Protect%20for%20Virtual%20Environments&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Obtain%20Information&color=brighgreen) ### Description IBM Spectrum Protect Backup-Archive Client and IBM Spectrum Protect for Virtual Environments 7.1 and 8.1 creates directories/files in the CIT sub directory that are read/writable by everyone. IBM X-Force ID: 155551. ### POC #### Reference No PoCs from references. #### Github - https://github.com/QAX-A-Team/CVE-2018-20250 - https://github.com/national008/lii