Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2015-1975


The web administration tool in IBM Tivoli Security Directory Server 6.0 before iFix 75, 6.1 before iFix 68, 6.2 before iFix 44, and 6.3 before iFix 37 and IBM Security Directory Server 6.3.1 before iFix 11 and 6.4 before iFix 2 allows local users to gain privileges via vectors related to argument injection. IBM X-Force ID: 103694.


Published

2018-04-03T22:29:00.290

Last Modified

2024-11-21T02:26:30.137

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.8 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.9

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-74

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application ibm tivoli_directory_server 6.0 Yes
Application ibm tivoli_directory_server 6.1.0 Yes
Application ibm tivoli_directory_server 6.2.0.0 Yes
Application ibm tivoli_directory_server 6.3.0.0 Yes
Application ibm tivoli_directory_server 6.3.1.0 Yes
Application ibm tivoli_directory_server 6.4.0 Yes

References