Lucene search

K
cveIbmCVE-2014-6154
HistoryFeb 13, 2015 - 2:59 a.m.

CVE-2014-6154

2015-02-1302:59:05
CWE-22
ibm
web.nvd.nist.gov
25
cve-2014-6154
directory traversal
ibm
optim performance manager
db2
nvd
vulnerability
linux
unix
windows

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.4%

Directory traversal vulnerability in IBM Optim Performance Manager for DB2 4.1.0.1 through 4.1.1 on Linux, UNIX, and Windows and IBM InfoSphere Optim Performance Manager for DB2 5.1 through 5.3.1 on Linux, UNIX, and Windows allows remote attackers to access arbitrary files via a … (dot dot) in a URL.

Affected configurations

Nvd
Node
ibmoptim_performance_managerMatch4.1.1
OR
ibmoptim_performance_managerMatch4.1.1.1
OR
ibmoptim_performance_managerMatch5.1.0
AND
linuxlinux_kernel
OR
microsoftwindows
VendorProductVersionCPE
ibmoptim_performance_manager4.1.1cpe:2.3:a:ibm:optim_performance_manager:4.1.1:*:*:*:*:*:*:*
ibmoptim_performance_manager4.1.1.1cpe:2.3:a:ibm:optim_performance_manager:4.1.1.1:*:*:*:*:*:*:*
ibmoptim_performance_manager5.1.0cpe:2.3:a:ibm:optim_performance_manager:5.1.0:*:*:*:*:*:*:*
linuxlinux_kernel*cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
microsoftwindows*cpe:2.3:o:microsoft:windows:*:*:*:*:*:*:*:*

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.4%

Related for CVE-2014-6154