HIGH🇵🇱 Wersja polska

CVE-2025-3356

CVSS 8.6v3.1pub. 2025-10-30upd. 2025-11-07

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
  • IBM Tivoli Monitoring

    APP
    Ibm
    6.3.0.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2025-3357CRITICAL9.8PL ✓same product

RCE w IBM Tivoli Monitoring — nieprawidłowa walidacja indeksu tablicy

CVE-2017-1789CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w IBM Tivoli Monitoring V6

CVE-2015-7411CRITICAL9.9PL ✓same product

Eskalacja uprawnień w IBM Tivoli Monitoring przez portal client

CVE-2025-3355HIGH7.5same product

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse direct...

CVE-2025-3354HIGH8.1same product

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, c...