---
id: CVE-2025-3356
title: >-
  IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a
  remote attacker to traverse directories on the system
summary: >-
  IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a
  remote attacker to traverse directories on the system. An attacker could send
  a specially crafted URL request containing "dot dot" sequences (/../) to view,
  over…
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H'
cwe:
  - CWE-22
vendor: ibm
product: tivoli_monitoring
affected:
  - tivoli_monitoring = 6.3.0.7
published: '2025-10-30'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-3356'
references:
  - url: 'https://www.ibm.com/support/pages/node/7249694'
    label: psirt@us.ibm.com
tags:
  - nvd
epss: 0.00424
epssPercentile: 0.34652
ingestedAt: '2026-10-07T21:54:14.902Z'
---

## Overview

IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.

## Affected

- `tivoli_monitoring = 6.3.0.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
