Vulnerability Details CVE-2015-5018
                IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.013
                        
                    
                    
                        
                            EPSS Ranking 79.4%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 8.0
                        
                    
                    
                        
                            CVSS v2 Score 8.5
                        
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2015-5018
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_9.0_firmware:9.0.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.10
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.11
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.12
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.13
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.14
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.15
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.16
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.4
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.6
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.7
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.8
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.9
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.3
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.5
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1.0
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1.2
                                        
                                     
                                 
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1.3