CVE-2015-5003

CWE-77Command Injection3 documents3 sources
Severity
8.5HIGH
EPSS
1.3%
top 20.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 3
Latest updateMay 17

Description

The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages1 packages

NVDibm/tivoli_monitoring6.2.2, 6.2.3, 6.3.0+2

🔴Vulnerability Details

2
GHSA
GHSA-8jq2-x4gm-3p2q: The portal in IBM Tivoli Monitoring (ITM) 62022-05-17
CVEList
CVE-2015-5003: The portal in IBM Tivoli Monitoring (ITM) 62016-01-03
CVE-2015-5003 (HIGH CVSS 8.5) | The portal in IBM Tivoli Monitoring | cvebase.io