CVE-2015-0107 is a directory traversal vulnerability affecting multiple IBM Tivoli and Maximo products, including specific versions of IT Asset Management for IT, Service Request Manager, Change and Configuration Management Database, and Maximo Asset Management. This medium-severity vulnerability allows remote authenticated users to access unauthorized files and directories, potentially leading to information disclosure. While no public exploits are widely available, an ExploitDB entry suggests potential for Remote Code Execution in a related product. Despite its age, the vulnerability has a high FAUCET Risk Score but shows no active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.1CPE matchmatch criteria | cpe:2.3:a:ibm:change_and_configuration_management_database:7.1:*:*:*:*:*:*:* | ||
7.2CPE matchmatch criteria | cpe:2.3:a:ibm:change_and_configuration_management_database:7.2:*:*:*:*:*:*:* | ||
7.1CPE matchmatch criteria | cpe:2.3:a:ibm:maximo_asset_management:7.1:*:*:*:*:*:*:* | ||
7.1.1CPE matchmatch criteria | cpe:2.3:a:ibm:maximo_asset_management:7.1.1:*:*:*:*:*:*:* | ||
7.1.1.1CPE matchmatch criteria | cpe:2.3:a:ibm:maximo_asset_management:7.1.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.