CVE-2015-0107 EXPLOIT
6.5
MEDIUM · CVSS 3.0 · EPSS 6% (pctl 93)
Patch early
A public exploit exists.
Description
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.
Scoring
| CVSS | 6.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 5.96% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2017-04-24 |
| Last modified | 2026-06-17 |
Affected (11)
| Vendor | Product |
|---|---|
| ibm | change and configuration management database |
| ibm | maximo asset management |
| ibm | maximo asset management essentials |
| ibm | maximo for government |
| ibm | maximo for life sciences |
| ibm | maximo for nuclear power |
| ibm | maximo for oil and gas |
| ibm | maximo for transportation |
| ibm | maximo for utilities |
| ibm | tivoli asset management for it |
| ibm | tivoli service request manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IBM Tivoli Service Automation Manager 7.2.4 - Remote Code Execution | 2014-12-12 |
References
→ the Explorer · watch your stack · NVD