CVE-2014-9768

IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability
Configurations

Configuration 1 (hide)

cpe:2.3:a:ibm:tivoli_netview_access_services:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:21

Type Values Removed Values Added
References () http://www.irongeek.com/i.php?page=videos/derbycon4/t217-hacking-mainframes-vulnerabilities-in-applications-exposed-over-tn3270-dominic-white - () http://www.irongeek.com/i.php?page=videos/derbycon4/t217-hacking-mainframes-vulnerabilities-in-applications-exposed-over-tn3270-dominic-white -
References () https://vimeo.com/96718889 - () https://vimeo.com/96718889 -

07 Nov 2023, 02:23

Type Values Removed Values Added
Summary ** DISPUTED ** IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability. IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability

Information

Published : 2016-03-18 14:59

Updated : 2024-11-21 02:21


NVD link : CVE-2014-9768

Mitre link : CVE-2014-9768

CVE.ORG link : CVE-2014-9768


JSON object : View

Products Affected

ibm

  • tivoli_netview_access_services
CWE
CWE-264

Permissions, Privileges, and Access Controls