Vulnerability Name: | CVE-2015-0104 (CCN-99582) | ||||||||||||
Assigned: | 2014-12-12 | ||||||||||||
Published: | 2014-12-12 | ||||||||||||
Updated: | 2017-04-27 | ||||||||||||
Summary: | IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspecified vectors. | ||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 5.1 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
3.8 Low (CCN Temporal CVSS v2 Vector: AV:A/AC:M/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C)
| ||||||||||||
Vulnerability Type: | CWE-284 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-0104 Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21694974 Source: CCN Type: IBM Security Bulletin 1694974 Security Bulletin: Cross-Site Scripting (XSS) and Remote Code Execution Vulnerabilities Affecting Asset and Service Management (CVE-2015-0104, CVE-2015-0107, CVE-2015-0108, CVE-2015-0109) Source: BID Type: Third Party Advisory, VDB Entry 97999 Source: CCN Type: BID-97999 Multiple IBM Products CVE-2015-0104 Unspecified Remote Code Execution Vulnerability Source: XF Type: UNKNOWN ibm-tsam-cve20150104-code-exec(99582) Source: EXPLOIT-DB Type: EXPLOIT Offensive Security Exploit Database [12-12-2014] | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |