Vulnerability Name: CVE-2015-1992 (CCN-103846) Assigned: 2015-08-10 Published: 2015-08-10 Updated: 2016-12-08 Summary: IBM Systems Director 5.2.x, 6.1.x, 6.2.0.x, 6.2.1.x, 6.3.0.0, 6.3.1.x, 6.3.2.x, 6.3.3.x, 6.3.5.0, and 6.3.6.0 improperly processes events, which allows local users to gain privileges via unspecified vectors. CVSS v3 Severity: 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
6.9 Medium (CCN CVSS v2 Vector: AV:L/AC:M/Au:N/C:C/I:C/A:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): MediumAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Privileges References: Source: MITRE Type: CNACVE-2015-1992 Source: CONFIRM Type: Vendor Advisoryhttp://www-01.ibm.com/support/docview.wss?uid=nas7d9a0db411a9071e986257e8c0029b365 Source: AIXAPAR Type: Broken LinkIT08185 Source: CONFIRM Type: Vendor Advisoryhttp://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5098524 Source: SECTRACK Type: Third Party Advisory, VDB Entry1033653 Source: XF Type: UNKNOWNibm-fsm-cve20151992-priv-escalation(103846) Source: CCN Type: IBM Security Bulletin 5098524An unspecified vulnerability in event processing could allow elevated privileges in IBM Systems Director (CVE-2015-1992) Source: CCN Type: IBM Security Bulletin 5098699Vulnerability with event processing affects IBM Flex System Manager (FSM) Vulnerable Configuration: Configuration 1 :cpe:/a:ibm:systems_director:5.20:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.1.0:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.1.1:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.2.2:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.3.1:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.6.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:ibm:systems_director:6.3.0.0:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.5.0:*:*:*:*:*:*:* OR cpe:/a:ibm:systems_director:6.3.6.0:*:*:*:*:*:*:* AND cpe:/a:ibm:flex_system_manager:1.3.0:*:*:*:*:*:*:* OR cpe:/a:ibm:flex_system_manager:1.2.0:*:*:*:*:*:*:* OR cpe:/a:ibm:flex_system_manager:1.2.1:*:*:*:*:*:*:* OR cpe:/a:ibm:flex_system_manager:1.3.1:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
ibm systems director 5.20
ibm systems director 6.3.0.0
ibm systems director 6.3.1.0
ibm systems director 6.3.1.1
ibm systems director 6.3.2.0
ibm systems director 6.3.2.1
ibm systems director 6.3.2.2
ibm systems director 6.3.3.0
ibm systems director 6.3.3.1
ibm systems director 6.3.5.0
ibm systems director 6.3.6.0
ibm systems director 6.3.0.0
ibm systems director 6.3.5.0
ibm systems director 6.3.6.0
ibm flex system manager 1.3.0
ibm flex system manager 1.2.0
ibm flex system manager 1.2.1
ibm flex system manager 1.3.1