CVE-2013-2961: Input Validation
The internal web server in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to perform unspecified redirection of HTTP requests, and bypass the proxy-server configuration, via crafted HTTP traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2961?
CVE-2013-2961 is classified as a high severity vulnerability due to its potential to allow unauthorized access to sensitive information.
How do I fix CVE-2013-2961?
To fix CVE-2013-2961, upgrade IBM Tivoli Monitoring to the latest fix pack provided by IBM.
Which versions are affected by CVE-2013-2961?
CVE-2013-2961 affects IBM Tivoli Monitoring versions 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3.
What component is affected by CVE-2013-2961?
The internal web server in the Basic Services component of IBM Tivoli Monitoring is affected by CVE-2013-2961.
Is there a workaround for CVE-2013-2961?
No specific workaround is provided for CVE-2013-2961; the recommended action is to apply the necessary updates.