QID 378337

Date Published: 2023-04-05

QID 378337: IBM Tivoli Monitoring Remote Code Execution (RCE) Vulnerability (6826711)

IBM Tivoli Monitoring automates monitoring of essential system resources to detect bottlenecks and potential problems.

The libexpart parser that is used by IBM Tivoli Monitoring for parsing various configuration xml files and parsing soap requests is potentially vulnerable to remote code execution

Affected Versions:
IBM Tivoli Monitoring 6.3.0.7 Service Pack 12

QID Detection Logic(Authenticated):
This QID checks for vulnerable version of IBM Tivoli Monitoring by reading the InstallITM/ver/INSTALL.ver file.

Successful exploitation of this vulnerability may allow an attacker to execute arbitrary code on the system.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Vendor has released patch to address this issue.For more details about product and patch information please refer vendor's advisory IBM Tivoli Monitoring Security Advisory (6826711).
    Vendor References

    CVEs related to QID 378337

    Software Advisories
    Advisory ID Software Component Link
    IBM Tivoli Monitoring Security Advisory (6826711) URL Logo www.ibm.com/support/pages/node/6826711