← Vulnerability feed

Vulnerability record · CVE-2013-2974 · published 29 January 2014

CVE-2013-2974: Ibm tivoli application dependency discovery manager permissions and access controls vulnerability

Ibm · Tivoli Application Dependency Discovery Manager

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.

7.5 CVSS 2.0 High EPSS 1.1% · top 34.5% CWE-264 · Permissions and access controls
7.5CVSS 2.0 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-2974 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-47143Ibm tivoli application dependency discovery manager vulnerabilityIBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 is vulnerable to HTTP header injection, caused by improper validation of…EPSS 0.78%8.8CVE-2023-47142Ibm tivoli application dependency discovery manager incorrect authorization vulnerabilityIBM Tivoli Application Dependency Discovery Manager 7.3.0.0 through 7.3.0.10 could allow an attacker on the organization's local network to escalate …EPSS 0.31%8.8CVE-2018-1455Ibm tivoli application dependency discovery manager cross-site request forgery vulnerabilityIBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execut…EPSS 0.78%8.1CVE-2013-3023Ibm tivoli application dependency discovery manager information exposure vulnerabilityIBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive informat…EPSS 1.9%7.5CVE-2018-1675Ibm tivoli application dependency discovery manager information exposure vulnerabilityIBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could expose password hashes in stored in system memory on target systems that are …EPSS 1.6%7.5CVE-2013-3017Ibm tivoli application dependency discovery manager vulnerabilityIBM Tivoli Application Dependency Discovery Manager (TADDM) before 7.2.1.5 and 7.2.x before 7.2.2 make it easier for remote attackers to defeat crypt…EPSS 2.3%7.1CVE-2013-4002Ibm java vulnerabilityXMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 bef…EPSS 25%6.5CVE-2016-8925Ibm tivoli application dependency discovery manager information exposure vulnerabilityIBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the atta…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2013-2974), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.