CVE-2015-5018

Severity
8.0HIGH
EPSS
1.3%
top 20.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 2
Latest updateMay 17

Description

IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.3 | Impact: 6.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-83v6-4v4j-7h89: IBM Security Access Manager for Web 72022-05-17
CVEList
CVE-2015-5018: IBM Security Access Manager for Web 72016-01-02