7.5

CVE-2025-3355

Medienbericht
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IbmTivoli Monitoring Version6.3.0.7 Update-
IbmTivoli Monitoring Version6.3.0.7 Updatesp1
IbmTivoli Monitoring Version6.3.0.7 Updatesp10
IbmTivoli Monitoring Version6.3.0.7 Updatesp11
IbmTivoli Monitoring Version6.3.0.7 Updatesp12
IbmTivoli Monitoring Version6.3.0.7 Updatesp13
IbmTivoli Monitoring Version6.3.0.7 Updatesp14
IbmTivoli Monitoring Version6.3.0.7 Updatesp15
IbmTivoli Monitoring Version6.3.0.7 Updatesp16
IbmTivoli Monitoring Version6.3.0.7 Updatesp17
IbmTivoli Monitoring Version6.3.0.7 Updatesp18
IbmTivoli Monitoring Version6.3.0.7 Updatesp19
IbmTivoli Monitoring Version6.3.0.7 Updatesp2
IbmTivoli Monitoring Version6.3.0.7 Updatesp20
IbmTivoli Monitoring Version6.3.0.7 Updatesp21
IbmTivoli Monitoring Version6.3.0.7 Updatesp3
IbmTivoli Monitoring Version6.3.0.7 Updatesp4
IbmTivoli Monitoring Version6.3.0.7 Updatesp5
IbmTivoli Monitoring Version6.3.0.7 Updatesp6
IbmTivoli Monitoring Version6.3.0.7 Updatesp7
IbmTivoli Monitoring Version6.3.0.7 Updatesp8
IbmTivoli Monitoring Version6.3.0.7 Updatesp9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.228
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@us.ibm.com 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.