CVE Vulnerabilities

CVE-2013-2974

Published: Jan 29, 2014 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.

Affected Software

NameVendorStart VersionEnd Version
Tivoli_application_dependency_discovery_managerIbm7.2.1.1 (including)7.2.1.1 (including)
Tivoli_application_dependency_discovery_managerIbm7.2.1.2 (including)7.2.1.2 (including)
Tivoli_application_dependency_discovery_managerIbm7.2.1.3 (including)7.2.1.3 (including)
Tivoli_application_dependency_discovery_managerIbm7.2.1.4 (including)7.2.1.4 (including)

References