Vulnerability Description
IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Netview Access Services | - |
Related Weaknesses (CWE)
References
- http://www.irongeek.com/i.php?page=videos/derbycon4/t217-hacking-mainframes-vuln
- https://vimeo.com/96718889
- http://www.irongeek.com/i.php?page=videos/derbycon4/t217-hacking-mainframes-vuln
- https://vimeo.com/96718889
FAQ
What is CVE-2014-9768?
CVE-2014-9768 is a vulnerability with a CVSS score of 8.8 (HIGH). IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a "page ID" field to the EMSPG2 transaction code. NOTE: the ve...
How severe is CVE-2014-9768?
CVE-2014-9768 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9768?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Tivoli Netview Access Services.