CVE-2015-4927
Last modified
CVE-2015-4927 is a vulnerability of currently unknown severity. The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing to a file.. EPSS estimates a 0.39% chance of exploitation in the next 30 days.
Description
The Reporting and Monitoring component in Tivoli Monitoring in IBM Tivoli Storage Manager 6.3 before 6.3.6 and 7.1 before 7.1.3 on Linux and AIX uses world-writable permissions for unspecified files, which allows local users to gain privileges by writing to a file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Storage Manager | 6.3.3 |
| Ibm | Tivoli Storage Manager | 6.3.4 |
| Ibm | Tivoli Storage Manager | 6.3.5 |
| Ibm | Tivoli Storage Manager | 6.3.5.1 |
| Ibm | Tivoli Storage Manager | 7.1 |
| Ibm | Tivoli Storage Manager | 7.1.1 |
| Ibm | Tivoli Storage Manager | 7.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-4927?
How severe is CVE-2015-4927?
How do I fix CVE-2015-4927?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-4921Unspecified vulnerability in the Database Vault component in…
- CVE-2015-4922Unspecified vulnerability in Oracle Sun Solaris 11 allows lo…
- CVE-2015-4923Unspecified vulnerability in the XML Developer's Kit for C c…
- CVE-2015-4924Unspecified vulnerability in the Oracle Agile PLM component …
- CVE-2015-4925Unspecified vulnerability in the Workspace Manager component…
- CVE-2015-4926Unspecified vulnerability in the Oracle Applications Framewo…
- CVE-2015-4928Apache Ambari before 2.1, as used in IBM Infosphere BigInsig…
- CVE-2015-4929IBM License Metric Tool 9 before 9.2.1.0 and Endpoint Manage…
- CVE-2015-4930IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x befor…
- CVE-2015-4931Stack-based buffer overflow in the server in IBM Tivoli Stor…
- CVE-2015-4932Stack-based buffer overflow in the server in IBM Tivoli Stor…
- CVE-2015-4933Stack-based buffer overflow in the server in IBM Tivoli Stor…
Are you affected by CVE-2015-4927?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
