CVE-2014-3915: Code Injection
The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) authsession, (3) authsimple, (4) add, (5) addflat, (6) remove, (7) setpwd, (8) addpermissions, (9) revokepermissions, (10) runAsync, or (11) tsmRequest command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3915?
CVE-2014-3915 has a critical severity rating due to its potential for remote command execution.
How do I fix CVE-2014-3915?
To mitigate CVE-2014-3915, update the affected Rocket Servergraph software to the latest version provided by the vendor.
What are the implications of CVE-2014-3915?
CVE-2014-3915 allows attackers to execute arbitrary commands on the server, which can lead to data breach or further exploitation.
Is my system vulnerable to CVE-2014-3915?
If you are using an affected version of Rocket Servergraph, your system may be vulnerable to CVE-2014-3915.
What action should be taken if CVE-2014-3915 is exploited?
If CVE-2014-3915 is exploited, immediate incident response measures should be taken to contain the breach and assess the extent of the impact.