CVE-2015-7411

CRITICAL

IBM Tivoli Monitoring <6.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035240
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IV77992
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21973559

Scores

CVSS v3 9.9
EPSS 0.0328
EPSS Percentile 87.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (12)
ibm/tivoli_monitoring 6.2.2
ibm/tivoli_monitoring 6.2.2.1
ibm/tivoli_monitoring 6.2.2.2
ibm/tivoli_monitoring 6.2.2.3
ibm/tivoli_monitoring 6.2.2.4
ibm/tivoli_monitoring 6.2.2.5
ibm/tivoli_monitoring 6.2.2.6
ibm/tivoli_monitoring 6.2.2.7
ibm/tivoli_monitoring 6.2.2.8
ibm/tivoli_monitoring 6.2.2.9
... and 2 more
Published Mar 12, 2016
Tracked Since Feb 18, 2026