CVE-2013-3004

low
Published 2014-07-01 · Modified 2026-05-06
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Directory traversal vulnerability in BIRT-Report Viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.x and 7.2.x before 7.2.1.5 allows remote authenticated users to read arbitrary files via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: psirt@us.ibm.com — http://www-01.ibm.com/support/docview.wss?uid=swg21672395

Application impact

VendorProductVersionsFixed
ibmtivoli_application_dependency_discovery_manager7.1.2
ibmtivoli_application_dependency_discovery_manager7.1.2.2
ibmtivoli_application_dependency_discovery_manager7.1.2.3
ibmtivoli_application_dependency_discovery_manager7.1.2.4
ibmtivoli_application_dependency_discovery_manager7.1.2.5
ibmtivoli_application_dependency_discovery_manager7.1.2.6
ibmtivoli_application_dependency_discovery_manager7.1.2.7
ibmtivoli_application_dependency_discovery_manager7.1.2.8
ibmtivoli_application_dependency_discovery_manager7.2.0
ibmtivoli_application_dependency_discovery_manager7.2.0.1
ibmtivoli_application_dependency_discovery_manager7.2.0.2
ibmtivoli_application_dependency_discovery_manager7.2.0.3
ibmtivoli_application_dependency_discovery_manager7.2.0.4
ibmtivoli_application_dependency_discovery_manager7.2.0.5
ibmtivoli_application_dependency_discovery_manager7.2.0.6
ibmtivoli_application_dependency_discovery_manager7.2.0.7
ibmtivoli_application_dependency_discovery_manager7.2.0.8
ibmtivoli_application_dependency_discovery_manager7.2.0.9
ibmtivoli_application_dependency_discovery_manager7.2.0.10
ibmtivoli_application_dependency_discovery_manager7.2.1
ibmtivoli_application_dependency_discovery_manager7.2.1.1
ibmtivoli_application_dependency_discovery_manager7.2.1.2
ibmtivoli_application_dependency_discovery_manager7.2.1.3
ibmtivoli_application_dependency_discovery_manager7.2.1.4
ibmtivoli_application_dependency_discovery_manager7.2.1.5

References

CWEs

CWE-22

Verify integrity in audit chain (admin only). AS-IS.