First published: Sat Jan 02 2016(Updated: )
IBM Security Access Manager for Web 7.0.0 before FP19 and 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1, allows remote authenticated users to execute arbitrary OS commands by leveraging Local Management Interface (LMI) access.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Security Access Manager 9.0 | =9.0.0 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.1 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.2 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.3 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.4 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.5 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.6 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.7 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.8 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.9 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.10 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.11 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.12 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.13 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.14 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.15 | |
IBM Security Access Manager for Web 7.0 | =7.0.0.16 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.1 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.2 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.3 | |
IBM Security Access Manager for Web 8.0 | =8.0.0.5 | |
IBM Security Access Manager for Web 8.0 | =8.0.1 | |
IBM Security Access Manager for Web 8.0 | =8.0.1.0 | |
IBM Security Access Manager for Web 8.0 | =8.0.1.2 | |
IBM Security Access Manager for Web 8.0 | =8.0.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5018 has been classified as a high severity vulnerability due to its potential for remote command execution.
To remediate CVE-2015-5018, upgrade to the latest version of IBM Security Access Manager that is not affected by this vulnerability.
CVE-2015-5018 affects IBM Security Access Manager for Web versions 7.0.0 before FP19, 8.0 before 8.0.1.3 IF3, and Security Access Manager 9.0 before 9.0.0.0 IF1.
CVE-2015-5018 can be exploited by remote authenticated users who have access to the Local Management Interface.
CVE-2015-5018 is an OS command injection vulnerability that allows the execution of arbitrary commands.