CVE-2014-6141

IBM Tivoli Monitoring 6.2.0-6.2.3 FP05, 6.3.0 < FP04 - Authenticated Command Injection via Take Action View

Title source: llm
STIX 2.1

Description

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21690932
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/96911

Scores

EPSS 0.0176
EPSS Percentile 75.6%

Details

CWE
CWE-264
Status published
Products (33)
ibm/tivoli_monitoring 6.2.0
ibm/tivoli_monitoring 6.2.0.1
ibm/tivoli_monitoring 6.2.0.2
ibm/tivoli_monitoring 6.2.0.3
ibm/tivoli_monitoring 6.2.1
ibm/tivoli_monitoring 6.2.1.0
ibm/tivoli_monitoring 6.2.1.1
ibm/tivoli_monitoring 6.2.1.2
ibm/tivoli_monitoring 6.2.1.3
ibm/tivoli_monitoring 6.2.1.4
... and 23 more
Published Feb 02, 2015
Tracked Since Feb 18, 2026