
CVE-2020-4311
https://notcve.org/view.php?id=CVE-2020-4311
23 Apr 2020 — IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially crafted file, an attacker could exploit this vulnerability to load other DLL files located in the same directory and execute arbitrary code on the system. IBM X-Force ID: 177083. IBM Tivoli Monitoring versión 6.3.0, podría permitir a un atacante local ejecutar código arbitrario en el sistema. Al colocar un archivo especialmente diseñado, un atacante podría explotar esta vulnerabilidad par... • https://exchange.xforce.ibmcloud.com/vulnerabilities/177083 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2019-4592
https://notcve.org/view.php?id=CVE-2019-4592
13 Feb 2020 — IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to access and modify operation aspects of the ITM monitoring server possibly leading to an effective denial of service or disabling of the monitoring server. IBM X-Force ID: 167647. IBM Tivoli Monitoring Service versiones 6.3.0.7.3 hasta 6.3.0.7.10, podría permitir a un usuario no autorizado acceder y modificar los aspectos operativos del servidor de monitoreo ITM, conllevando posiblemente a una denegación del servic... • https://exchange.xforce.ibmcloud.com/vulnerabilities/167647 •

CVE-2017-1794
https://notcve.org/view.php?id=CVE-2017-1794
19 Sep 2018 — IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039. IBM Tivoli Monitoring desde la versión 6.2.3 hasta la 6.2.3.5 y desde la 6.3.0 hasta la 6.3.0.7 es vulnerable a un escalado de privilegios del usuario TEPS y una posible denegación de servicio (DoS) debido a un crecimiento de memoria sin restricciones. IBM X-Force ID: 137039. • https://exchange.xforce.ibmcloud.com/vulnerabilities/137039 • CWE-400: Uncontrolled Resource Consumption •

CVE-2017-1789
https://notcve.org/view.php?id=CVE-2017-1789
22 Mar 2018 — IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034. IBM Tivoli Monitoring V6 6.2.3 y 6.3.0 podría permitir que un usuario no autenticado ejecute código de forma remota mediante métodos sin especificar. IBM X-Force ID: 137034. • http://www.ibm.com/support/docview.wss?uid=swg22014096 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2017-1635
https://notcve.org/view.php?id=CVE-2017-1635
13 Dec 2017 — IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243. IBM Tivoli Monitoring V6 6.2.2.x podría permitir que un atacante remoto ejecute código arbitrario en el sistema, provocado por un error de uso de memoria previamente liberada. Un atacante remoto podría explotar esta vulnerab... • https://github.com/emcalv/tivoli-poc • CWE-416: Use After Free •

CVE-2017-1181
https://notcve.org/view.php?id=CVE-2017-1181
14 Jul 2017 — IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487. IBM Tivoli Monitoring Portal V6 permite a un atacante local escalar privilegios para IBM Tivoli Monitoring, causando que la conexión por defecto de la consola no sea encriptada. IBM X-Force ID: 123487. • http://www.ibm.com/support/docview.wss?uid=swg22003402 • CWE-319: Cleartext Transmission of Sensitive Information •

CVE-2017-1183
https://notcve.org/view.php?id=CVE-2017-1183
14 Jul 2017 — IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494. IBM Tivoli Monitoring Portal v6 permite a un atacante local o de una red adyacente modificar comando SQL al Portal Server, cuando las comunicaciones por defecto entre el cliente y el servidor HTTP están siendo usadas. IBM X-Force ID: 123494. • http://www.ibm.com/support/docview.wss?uid=swg22003402 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2017-1182
https://notcve.org/view.php?id=CVE-2017-1182
14 Jul 2017 — IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493. IBM Tivoli Monitoring Portal v6 permite a un atacante local o de una red adyacente ejecutar comando aleatorios en el sistema, cuando las comunicaciones por defecto entre el cliente y el servidor HTTP están siendo usadas. IBM X-Force ID: 123494. • https://github.com/Morfeen01/cve-2017-1182-TN •

CVE-2016-6083
https://notcve.org/view.php?id=CVE-2016-6083
27 Jun 2017 — IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696. IBM Tivoli Monitoring V6 podría permitir a un usuario no autenticado acceder a consultas SOAP que podrían contener información confidencial. IBM X-Force ID: 117696. • http://www.ibm.com/support/docview.wss?uid=swg22000909 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-5933
https://notcve.org/view.php?id=CVE-2016-5933
08 Mar 2017 — IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223. IBM Tivoli Monitoring 6.2 y 6.3 es vulnerable a posibles ataques de inyección de encabezado de host que podría conducir a envenenamiento de caché HTTP o elusión del firewall. Referencia IBM #: 1997223. • http://www.ibm.com/support/docview.wss?uid=swg21997223 • CWE-254: 7PK - Security Features •