CVE-2013-2974
high
CVSS v3
—
CVSS v2
7.5
VIR risk
7.5
Description
The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/docview.wss?uid=swg21662955
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.1 | |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.2 | |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.3 | |
| ibm | tivoli_application_dependency_discovery_manager | 7.2.1.4 | |
References
CWEs
CWE-264
Verify integrity in audit chain (admin only). AS-IS.