VulnerabilityModified
CVE-2015-7411
The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors.
CRITICAL 9.9EPSS 3.28%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors.
- CVSS 3.0
- 9.9 CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 3.28% probability · 88th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- ibm/tivoli monitoring
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV77992
- http://www-01.ibm.com/support/docview.wss?uid=swg21973559Vendor Advisory
- http://www.securitytracker.com/id/1035240
- http://www-01.ibm.com/support/docview.wss?uid=swg1IV77992
- http://www-01.ibm.com/support/docview.wss?uid=swg21973559Vendor Advisory
- http://www.securitytracker.com/id/1035240
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.