PT-2025-44450 · Ibm · Ibm Tivoli Monitoring
Aleksandr Tlyapov
·
Published
2025-10-30
·
Updated
2025-11-07
·
CVE-2025-3355
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Monitoring versions 6.3.0.7 through 6.3.0.7 Service Pack 21
Description
The software potentially allows a remote attacker to access files on the system outside of the intended directories. This is achieved by sending a crafted URL request that includes "dot dot" sequences (/../). The request can be sent to an API endpoint, allowing access to arbitrary files. The vulnerable parameter is the URL itself.
Recommendations
Apply updates to versions beyond 6.3.0.7 Service Pack 21.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Tivoli Monitoring