17 results (0.008 seconds)

CVSS: 8.0EPSS: 0%CPEs: 9EXPL: 2

13 Dec 2017 — IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243. IBM Tivoli Monitoring V6 6.2.2.x podría permitir que un atacante remoto ejecute código arbitrario en el sistema, provocado por un error de uso de memoria previamente liberada. Un atacante remoto podría explotar esta vulnerab... • https://github.com/emcalv/tivoli-poc • CWE-416: Use After Free •

CVSS: 5.3EPSS: 0%CPEs: 26EXPL: 0

27 Jun 2017 — IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696. IBM Tivoli Monitoring V6 podría permitir a un usuario no autenticado acceder a consultas SOAP que podrían contener información confidencial. IBM X-Force ID: 117696. • http://www.ibm.com/support/docview.wss?uid=swg22000909 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 4.9EPSS: 0%CPEs: 23EXPL: 0

08 Mar 2017 — IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223. IBM Tivoli Monitoring 6.2 y 6.3 es vulnerable a posibles ataques de inyección de encabezado de host que podría conducir a envenenamiento de caché HTTP o elusión del firewall. Referencia IBM #: 1997223. • http://www.ibm.com/support/docview.wss?uid=swg21997223 • CWE-254: 7PK - Security Features •

CVSS: 7.8EPSS: 0%CPEs: 13EXPL: 0

01 Dec 2016 — Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors. Desbordamiento de búfer basado en pila en las ax Shared Libraries en el Agent en IBM Tivoli Monitoring (ITM) 6.2.2 en versiones anteriores a FP9, 6.2.3 en versiones anteriores a FP5 y 6.3.0 en versiones anteriores FP2 en Linux y UNIX permite a usuarios locales obtener privil... • http://www-01.ibm.com/support/docview.wss?uid=swg1IV85845 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.9EPSS: 0%CPEs: 12EXPL: 0

12 Mar 2016 — The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors. El portal cliente en IBM Tivoli Monitoring (ITM) 6.2.2 hasta la versión FP9, 6.2.3 hasta la versión FP5 y 6.3.0 hasta la versión FP6 permite a usuarios remotos autenticados obtener privilegios a través de vectores no especificados. • http://www-01.ibm.com/support/docview.wss?uid=swg1IV77992 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 8.5EPSS: 0%CPEs: 3EXPL: 0

03 Jan 2016 — The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input. El portal en IBM Tivoli Monitoring (ITM) 6.2.2 hasta la versión FP9, 6.2.3 hasta la versión FP5 y 6.3.0 en versiones anteriores a FP7 permite a usuarios remotos autenticados ejecutar comandos arbitrarios aprovechando la autoridad de la vista Take Action y proveyendo una entrad... • http://www-01.ibm.com/support/docview.wss?uid=swg1IV77742 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') •

CVSS: 8.8EPSS: 0%CPEs: 33EXPL: 0

02 Feb 2015 — IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands. IBM Tivoli Monitoring (ITM) 6.2.0 hasta FP03, 6.2.1 hasta FP04, 6.2.2 hasta FP09, 6.2.3 hasta FP05, y 6.3.0 anterior a FP04 permite a usuarios remotos autenticados evadir las restricciones de acceso y ejec... • http://www-01.ibm.com/support/docview.wss?uid=swg21690932 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 6.1EPSS: 0%CPEs: 23EXPL: 0

21 Jun 2013 — Multiple cross-site scripting (XSS) vulnerabilities in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. Múltiples vulnerabilidades de ejecución de secuencias de comandos en ... • http://www-01.ibm.com/support/docview.wss?uid=swg1IV27192 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 7.5EPSS: 2%CPEs: 23EXPL: 0

21 Jun 2013 — The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service (abend) via a crafted URL. El componente Basic Services en IBM Tivoli Monitoring (ITM) v6.2.0 hasta FP3, v6.2.1 hasta FP4, v6.2.2 hasta FP9, y v6.2.3 hasta FP... • http://www-01.ibm.com/support/docview.wss?uid=swg1IV27192 • CWE-20: Improper Input Validation •

CVSS: 8.2EPSS: 0%CPEs: 23EXPL: 0

21 Jun 2013 — The internal web server in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to perform unspecified redirection of HTTP requests, and bypass the proxy-server configuration, via crafted HTTP traffic. El servidor web interno en el componen... • http://www-01.ibm.com/support/docview.wss?uid=swg1IV27192 • CWE-20: Improper Input Validation •