IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:HIBM Tivoli Monitoring
APPIbm6.3.0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References
Related vulnerabilities
CVE-2025-3357CRITICAL9.8PL ✓same product
RCE w IBM Tivoli Monitoring — nieprawidłowa walidacja indeksu tablicy
CVE-2017-1789CRITICAL9.8PL ✓same product
RCE bez uwierzytelnienia w IBM Tivoli Monitoring V6
CVE-2015-7411CRITICAL9.9PL ✓same product
Eskalacja uprawnień w IBM Tivoli Monitoring przez portal client
CVE-2025-3355HIGH7.5same product
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse direct...
CVE-2025-3354HIGH8.1same product
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, c...