Show plain JSON{"id": "CVE-2015-5018", "cveTags": [], "metrics": {"cvssMetricV2": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"version": "2.0", "baseScore": 8.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:M/Au:S/C:C/I:C/A:C", "authentication": "SINGLE", "integrityImpact": "COMPLETE", "accessComplexity": "MEDIUM", "availabilityImpact": "COMPLETE", "confidentialityImpact": "COMPLETE"}, "acInsufInfo": false, "impactScore": 10.0, "baseSeverity": "HIGH", "obtainAllPrivilege": false, "exploitabilityScore": 6.8, "obtainUserPrivilege": false, "obtainOtherPrivilege": false}], "cvssMetricV30": [{"type": "Primary", "source": "nvd@nist.gov", "cvssData": {"scope": "CHANGED", "version": "3.0", "baseScore": 8.0, "attackVector": "NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "HIGH", "availabilityImpact": "HIGH", "privilegesRequired": "HIGH", "confidentialityImpact": "HIGH"}, "impactScore": 6.0, "exploitabilityScore": 1.3}]}, "published": "2016-01-02T05:59:03.800", "references": [{"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV78768", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg1IV78780", "source": "psirt@us.ibm.com"}, {"url": "http://www-01.ibm.com/support/docview.wss?uid=swg21970510", "tags": ["Vendor Advisory"], "source": "psirt@us.ibm.com"}, {"url": "http://www.securitytracker.com/id/1034560", "source": "psirt@us.ibm.com"}], "vulnStatus": "Modified", "weaknesses": [{"type": "Primary", "source": "nvd@nist.gov", "description": [{"lang": "en", "value": "CWE-78"}]}], "descriptions": [{"lang": "en", "value": "IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access."}, {"lang": "es", "value": "IBM Security Access Manager for Web 7.0.0 en versiones anteriores a FP19 y 8.0 en versiones anteriores a 8.0.1.3 IF3 y Security Access Manager 9.0 en versiones anteriores a 9.0.0.0 IF1, permite a usuarios remotos autenticados ejecutar comandos del SO arbitrarios aprovechando el acceso Local Management Interface (LMI)."}], "lastModified": "2016-12-07T18:15:37.747", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:ibm:security_access_manager_9.0_firmware:9.0.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6B5B6BD9-C0DF-4359-A6C1-F66E24912800"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "22433CE0-9772-48CE-8069-612FF3732C21"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2569AA28-5C61-4BBD-A501-E1ACFA36837B"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "79AFD6BE-4ED1-4A9C-AF30-F083A7A4F418"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3AB188A2-D7CE-4141-A55A-C074C84E366E"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "DE776097-1DA4-4F27-8E96-61E3D9FFE8D0"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FE4E5283-0FEE-4F37-9C41-FA695063FF79"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "39D9B9CF-5F3D-4CA3-87A0-AAE1BA5F09C1"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73EB6121-62CD-49FC-A1D2-5467B007253C"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A91ADDFE-9362-4D7E-B623-D662D81382E8"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.10:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C8E0F31E-EB32-4442-91BE-95A9625F308F"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.11:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "701D729E-A817-4525-ADD9-EC810326B9E2"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.12:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5883F2E-83F4-4630-813B-21E533BA2CB7"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.13:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A1FB9953-91A1-47BB-B6BF-088FA75BEBCA"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.14:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "CD7B0192-465A-48EF-8B51-FC6BC6EC464A"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.15:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E40F5AD-E090-4D0B-A580-D794F60215DB"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_7.0_firmware:7.0.0.16:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "EC5BD4D1-DD9B-4845-AF17-9B813C748D1A"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4B0D27CF-70BF-4C72-A963-310272D8EBF7"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "97E19969-DD73-42F2-9E91-504E1663B268"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F9CC2E05-5179-4241-A710-E582510EEB0D"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.0.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD1366C8-9C78-4B40-8E40-19C4DFEC2B1D"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D331E67E-25D3-4C34-8118-49E2A8B29D96"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "73E4F0CD-26DF-4975-8F40-ECB8E03A08C2"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "FFE6F2A0-BD38-4853-A8FB-299A341FA0B6"}, {"criteria": "cpe:2.3:o:ibm:security_access_manager_for_web_8.0_firmware:8.0.1.3:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D0122CE6-44D9-4A5F-8DD4-B1F7F229FDFB"}], "operator": "OR"}]}], "sourceIdentifier": "psirt@us.ibm.com"}