Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-6141

Overview

Vulnerability Score 8.5 8.5
CVE Id CVE-2014-6141
Last Modified 02 Feb 2015 05:47:56
Published 01 Feb 2015 08:59:01
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication SINGLE_INSTANCE

CVE-2014-6141

Summary

IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.

Vulnerable Systems

Application

  • Ibm Tivoli Monitoring 6.2.0

  • Ibm Tivoli Monitoring 6.2.0.1

  • Ibm Tivoli Monitoring 6.2.0.2

  • Ibm Tivoli Monitoring 6.2.0.3

  • Ibm Tivoli Monitoring 6.2.1

  • Ibm Tivoli Monitoring 6.2.1.0

  • Ibm Tivoli Monitoring 6.2.1.1

  • Ibm Tivoli Monitoring 6.2.1.2

  • Ibm Tivoli Monitoring 6.2.1.3

  • Ibm Tivoli Monitoring 6.2.1.4

  • Ibm Tivoli Monitoring 6.2.2

  • Ibm Tivoli Monitoring 6.2.2.0

  • Ibm Tivoli Monitoring 6.2.2.1

  • Ibm Tivoli Monitoring 6.2.2.2

  • Ibm Tivoli Monitoring 6.2.2.3

  • Ibm Tivoli Monitoring 6.2.2.4

  • Ibm Tivoli Monitoring 6.2.2.5

  • Ibm Tivoli Monitoring 6.2.2.6

  • Ibm Tivoli Monitoring 6.2.2.7

  • Ibm Tivoli Monitoring 6.2.2.8

  • Ibm Tivoli Monitoring 6.2.2.9

  • Ibm Tivoli Monitoring 6.2.3

  • Ibm Tivoli Monitoring 6.2.3.0

  • Ibm Tivoli Monitoring 6.2.3.1

  • Ibm Tivoli Monitoring 6.2.3.2

  • Ibm Tivoli Monitoring 6.2.3.3

  • Ibm Tivoli Monitoring 6.2.3.4

  • Ibm Tivoli Monitoring 6.2.3.5

  • Ibm Tivoli Monitoring 6.3.0

  • Ibm Tivoli Monitoring 6.3.0.1

  • Ibm Tivoli Monitoring 6.3.0.2

  • Ibm Tivoli Monitoring 6.3.0.3

  • Ibm Tivoli Monitoring 6.3.0.4


References

XF - ibm-itm-cve20146141-sec-bypass(96911)

CONFIRM - http://www-01.ibm.com/support/docview.wss?uid=swg21690932


Last Updated: 27 May 2016 11:07:40