{ "schema_version": "1.4.0", "id": "GHSA-qc8h-m9cf-7w7r", "modified": "2022-05-17T03:57:52Z", "published": "2022-05-17T03:57:52Z", "aliases": [ "CVE-2014-9768" ], "details": "** DISPUTED ** IBM Tivoli NetView Access Services (NVAS) allows remote authenticated users to gain privileges by entering the ADM command and modifying a \"page ID\" field to the EMSPG2 transaction code. NOTE: the vendor's perspective is that configuration and use of available security controls in the NVAS product mitigates the reported vulnerability.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2014-9768" }, { "type": "WEB", "url": "https://vimeo.com/96718889" }, { "type": "WEB", "url": "http://www.irongeek.com/i.php?page=videos/derbycon4/t217-hacking-mainframes-vulnerabilities-in-applications-exposed-over-tn3270-dominic-white" } ], "database_specific": { "cwe_ids": [], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2016-03-18T14:59:00Z" } }