3 results (0.003 seconds)

CVSS: 9.0EPSS: 1%CPEs: 1EXPL: 0

18 Mar 2016 — IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability ** DISPUTADA ** IBM Tivoli NetView Access Services (NVAS) permite a usuarios remotos autenticados obtener privilegios introduciendo un comando ADM y modificando un campo "page ... • http://www.irongeek.com/i.php?page=videos/derbycon4/t217-hacking-mainframes-vulnerabilities-in-applications-exposed-over-tn3270-dominic-white • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 7.8EPSS: 0%CPEs: 7EXPL: 0

26 Dec 2012 — Unspecified vulnerability in IBM Tivoli NetView 1.4, 5.1 through 5.4, and 6.1 on z/OS allows local users to gain privileges by leveraging access to the normal Unix System Services (USS) security level. Una vulnerabilidad no especificada en IBM Tivoli NetView v1.4, v5.1 a v5.4 y v6.1 en z/OS permite a usuarios locales obtener privilegios aprovechándose de su acceso al nivel de seguridad "normal" de Unix System Services (USS). • http://www-01.ibm.com/support/docview.wss?uid=swg1OA41059 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 10.0EPSS: 3%CPEs: 4EXPL: 2

29 Aug 2001 — ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execute arbitrary commands via shell metacharacters in a certain SNMP trap message. • https://www.exploit-db.com/exploits/20909 •