PT-2016-3649 · Ibm · Ibm Tivoli Monitoring

Lukasz Miedziński

·

Published

2016-01-03

·

Updated

2016-12-06

·

CVE-2015-5003

CVSS v2.0

8.5

High

VectorAV:N/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM Tivoli Monitoring (ITM) versions 6.2.2 through 6.2.2 FP9 IBM Tivoli Monitoring (ITM) versions 6.2.3 through 6.2.3 FP5 IBM Tivoli Monitoring (ITM) versions 6.3.0 before 6.3.0 FP7
Description The issue allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input.
Recommendations For versions 6.2.2 through 6.2.2 FP9, update to a version after 6.2.2 FP9. For versions 6.2.3 through 6.2.3 FP5, update to a version after 6.2.3 FP5. For versions 6.3.0 before 6.3.0 FP7, update to 6.3.0 FP7 or later.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5003

Affected Products

Ibm Tivoli Monitoring