| Vulnerability Name: | CVE-2015-5003 | ||||||||||||
| Assigned: | 2015-06-24 | ||||||||||||
| Published: | 2016-01-03 | ||||||||||||
| Updated: | 2016-12-06 | ||||||||||||
| Summary: | The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input. | ||||||||||||
| CVSS v3 Severity: | 8.5 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
| CVSS v2 Severity: | 8.5 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C)
| ||||||||||||
| Vulnerability Type: | CWE-77 | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2015-5003 Source: AIXAPAR Type: UNKNOWN IV77742 Source: CONFIRM Type: Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21970361 Source: SECTRACK Type: UNKNOWN 1034924 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||