** DISPUTED ** IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability.
References
Configurations
Information
Published : 2016-03-18 07:59
Updated : 2016-03-21 16:19
NVD link : CVE-2014-9768
Mitre link : CVE-2014-9768
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
ibm
- tivoli_netview_access_services