CVE-2013-2974

IBM Tivoli Application Dependency Discovery Manager 7.2.1.x - Privilege Escalation and SQL Injection

Title source: llm
STIX 2.1

Description

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/docview.wss?uid=swg21662955
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/83877

Scores

EPSS 0.0114
EPSS Percentile 63.3%

Details

CWE
CWE-264
Status published
Products (4)
ibm/tivoli_application_dependency_discovery_manager 7.2.1.1
ibm/tivoli_application_dependency_discovery_manager 7.2.1.2
ibm/tivoli_application_dependency_discovery_manager 7.2.1.3
ibm/tivoli_application_dependency_discovery_manager 7.2.1.4
Published Jan 29, 2014
Tracked Since Feb 18, 2026