CyberRota Analysis
AI-GeneratedFortra BoKS Manager is vulnerable due to an insecure temporary file issue in the bccgethostcert utility, which creates predictable temporary files without a restrictive umask. This flaw allows local users on the BoKS Master to potentially access sensitive data, including CA secrets and host private-key material, during or after the utility's execution. Organizations using BoKS Manager should prioritize remediation to mitigate the risk of unauthorized access to critical cryptographic materials.
Original NVD Description
Fortra BoKS Manager contains an insecure temporary file vulnerability in bccgethostcert. The utility creates predictable temporary files without first setting a restrictive umask. A local user on the BoKS Master who can read files under BOKS_tmp may be able to obtain CA secret or host private-key material while the utility runs, or obtain CA secret material left behind after successful certificate creation.