CVE-2015-1974

CWE-2643 documents3 sources
Severity
6.5MEDIUM
EPSS
0.3%
top 46.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 28
Latest updateMay 17

Description

The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, 6.3 before iFix 37, 6.3.1 before iFix 11, and 6.4 before iFix 2 allows remote authenticated users to bypass intended command restrictions via unspecified vectors.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDibm/tivoli_directory_server6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-f3p2-j336-wh42: The web administration tool in IBM Tivoli Security Directory Server 62022-05-17
CVEList
CVE-2015-1974: The web administration tool in IBM Tivoli Security Directory Server 62015-06-28
CVE-2015-1974 (MEDIUM CVSS 6.5) | The web administration tool in IBM | cvebase.io