QID 378337
Date Published: 2023-04-05
QID 378337: IBM Tivoli Monitoring Remote Code Execution (RCE) Vulnerability (6826711)
IBM Tivoli Monitoring automates monitoring of essential system resources to detect bottlenecks and potential problems.
The libexpart parser that is used by IBM Tivoli Monitoring for parsing various configuration xml files and parsing soap requests is potentially vulnerable to remote code execution
Affected Versions:
IBM Tivoli Monitoring 6.3.0.7 Service Pack 12
QID Detection Logic(Authenticated):
This QID checks for vulnerable version of IBM Tivoli Monitoring by reading the InstallITM/ver/INSTALL.ver file.
Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the system.
Solution
Vendor has released patch to address this issue.For more details about product and patch information please refer vendor's advisory IBM Tivoli Monitoring Security Advisory (6826711).
Vendor References
- IBM Tivoli Monitoring Security Advisory (6826711) -
www.ibm.com/support/pages/node/6826711
CVEs related to QID 378337
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| IBM Tivoli Monitoring Security Advisory (6826711) |
|