First published: Fri Mar 18 2016(Updated: )
** DISPUTED ** IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli NetView |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9768 has a medium severity rating due to the potential for privilege escalation by remote authenticated users.
To mitigate CVE-2014-9768, implement proper access controls and review security configurations of IBM Tivoli NetView Access Services.
CVE-2014-9768 affects installations of IBM Tivoli NetView Access Services allowing certain authenticated users to exploit the vulnerability.
Yes, CVE-2014-9768 can be exploited remotely by authenticated users who have access to the vulnerable system.
The impact of CVE-2014-9768 is the potential for unauthorized privilege escalation within the application.