| Vulnerability Name: | CVE-2015-1975 (CCN-103694) | ||||||||||||
| Assigned: | 2015-06-24 | ||||||||||||
| Published: | 2015-06-24 | ||||||||||||
| Updated: | 2018-05-10 | ||||||||||||
| Summary: | The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection. IBM X-Force ID: 103694. | ||||||||||||
| CVSS v3 Severity: | 7.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
| ||||||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
3.0 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:M/Au:S/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||||||
| Vulnerability Type: | CWE-74 | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2015-1975 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21960659 Source: CCN Type: IBM Security Bulletin 1960659 (IBM Security Directory Server) Multiple Vulnerabilities fixed in IBM Security Directory Server Source: BID Type: Third Party Advisory, VDB Entry 103717 Source: CCN Type: BID-103717 IBM Security Directory Server CVE-2015-1975 Remote Security Bypass Vulnerability Source: XF Type: UNKNOWN ibm-sds-cve20151975-arg-injection(103694) Source: XF Type: VDB Entry, Vendor Advisory ibm-sds-cve20151975-arg-injection(103694) | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||