CVE-2015-0107 PUBLISHED CVSS 6.5 MEDIUM

IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.

EPSS 7.17% · 91.5th percentile

Risk Scores

CVSS v3.0
6.5
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
7.17%
91.5th percentile

Affected Products

VendorProductVersions
ibmmaximo_asset_management7.1.1.7, 7.1.1.6, 7.1.1.8
ibmmaximo_asset_management_essentials7.1
ibmmaximo_for_oil_and_gas7.1
n/an/an/a
ibmtivoli_asset_management_for_it7.2, 7.1
ibmmaximo_for_transportation7.1
ibmmaximo_for_utilities7.1
ibmmaximo_for_government7.1
ibmtivoli_service_request_manager7.2, 7.1
ibmmaximo_for_life_sciences7.1
ibmchange_and_configuration_management_database7.2, 7.1
ibmmaximo_for_nuclear_power7.1

Timeline

References

Open in Interactive Console →