CVE-2015-5018
Summary
| CVE | CVE-2015-5018 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-01-02 05:59:00 UTC |
| Updated | 2016-12-07 18:15:00 UTC |
| Description | IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access. |
Risk And Classification
Problem Types: CWE-78
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-01.ibm.com | |
| IBM notice: The page you requested cannot be displayed | AIXAPAR | www-01.ibm.com | |
| IBM Security Access Manager for Web Flaw Lets Remote Authenticated Users Execute Arbitrary Commands on the Target System - SecurityTracker | SECTRACK | www.securitytracker.com | |
| IBM Security Bulletin: IBM Security Access Manager for Web is affected by a command injection vulnerability (CVE-2015-5018) - United States | CONFIRM | www-01.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.