CVE-2014-6149
Directory traversal vulnerability in BIRT-viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to read arbitrary files via…
Does this matter?
Lower severity and a low EPSS score (1.85%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in BIRT-viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.0.0 through 7.2.0.10, 7.2.1.0 through 7.2.1.6, and 7.2.2.0 through 7.2.2.2 allows remote authenticated users to read arbitrary files via unspecified vectors.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.85% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- ibm/tivoli application dependency discovery manager
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg21688296Vendor Advisory
- http://www.securityfocus.com/bid/70805
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96919
- http://www-01.ibm.com/support/docview.wss?uid=swg21688296Vendor Advisory
- http://www.securityfocus.com/bid/70805
- https://exchange.xforce.ibmcloud.com/vulnerabilities/96919
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.