CVE-2025-3355
30.10.2025, 20:15
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
| Vendor | Product | Version |
|---|---|---|
| ibm | tivoli_monitoring | 6.3.0.7 |
| ibm | tivoli_monitoring | 6.3.0.7:sp1 |
| ibm | tivoli_monitoring | 6.3.0.7:sp10 |
| ibm | tivoli_monitoring | 6.3.0.7:sp11 |
| ibm | tivoli_monitoring | 6.3.0.7:sp12 |
| ibm | tivoli_monitoring | 6.3.0.7:sp13 |
| ibm | tivoli_monitoring | 6.3.0.7:sp14 |
| ibm | tivoli_monitoring | 6.3.0.7:sp15 |
| ibm | tivoli_monitoring | 6.3.0.7:sp16 |
| ibm | tivoli_monitoring | 6.3.0.7:sp17 |
| ibm | tivoli_monitoring | 6.3.0.7:sp18 |
| ibm | tivoli_monitoring | 6.3.0.7:sp19 |
| ibm | tivoli_monitoring | 6.3.0.7:sp2 |
| ibm | tivoli_monitoring | 6.3.0.7:sp20 |
| ibm | tivoli_monitoring | 6.3.0.7:sp21 |
| ibm | tivoli_monitoring | 6.3.0.7:sp3 |
| ibm | tivoli_monitoring | 6.3.0.7:sp4 |
| ibm | tivoli_monitoring | 6.3.0.7:sp5 |
| ibm | tivoli_monitoring | 6.3.0.7:sp6 |
| ibm | tivoli_monitoring | 6.3.0.7:sp7 |
| ibm | tivoli_monitoring | 6.3.0.7:sp8 |
| ibm | tivoli_monitoring | 6.3.0.7:sp9 |
𝑥
= Vulnerable software versions