AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2014-3915

HIGH · CVSS 10 EPSS 3.12%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2014-06-11 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2014-3915
Severity
HIGH
CVSS
10
EPSS
3.12%

Original Filing — NVD Description

The userRequest servlet in the Admin Center for Tivoli Storage Manager in Rocket Servergraph allows remote attackers to execute arbitrary commands via a (1) auth, (2) auth_session, (3) auth_simple, (4) add, (5) add_flat, (6) remove, (7) set_pwd, (8) add_permissions, (9) revoke_permissions, (10) runAsync, or (11) tsmRequest command.