Vulnerability Details CVE-2015-0107
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.072
EPSS Ranking 91.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2015-0107
-
cpe:2.3:a:ibm:change_and_configuration_management_database:7.1
-
cpe:2.3:a:ibm:change_and_configuration_management_database:7.2
-
cpe:2.3:a:ibm:maximo_asset_management:7.1
-
cpe:2.3:a:ibm:maximo_asset_management:7.1.1
-
cpe:2.3:a:ibm:maximo_asset_management:7.1.1.1
-
cpe:2.3:a:ibm:maximo_asset_management:7.1.1.2
-
cpe:2.3:a:ibm:maximo_asset_management:7.1.1.5
-
cpe:2.3:a:ibm:maximo_asset_management:7.1.1.6
-
cpe:2.3:a:ibm:maximo_asset_management:7.1.1.7
-
cpe:2.3:a:ibm:maximo_asset_management:7.1.1.8
-
cpe:2.3:a:ibm:maximo_asset_management_essentials:7.1
-
cpe:2.3:a:ibm:maximo_for_government:7.1
-
cpe:2.3:a:ibm:maximo_for_life_sciences:7.1
-
cpe:2.3:a:ibm:maximo_for_nuclear_power:7.1
-
cpe:2.3:a:ibm:maximo_for_oil_and_gas:7.1
-
cpe:2.3:a:ibm:maximo_for_transportation:7.1
-
cpe:2.3:a:ibm:maximo_for_utilities:7.1
-
cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.1
-
cpe:2.3:a:ibm:tivoli_asset_management_for_it:7.2
-
cpe:2.3:a:ibm:tivoli_service_request_manager:7.1
-
cpe:2.3:a:ibm:tivoli_service_request_manager:7.2