CVE-2017-1181: High severity IBM Tivoli Monitoring vulnerability
Published Jul 14, 2017
·Updated
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.
Affected Software
3 affected components
IBM Tivoli Monitoring=6.2.2.9
IBM Tivoli Monitoring=6.2.3.5
IBM Tivoli Monitoring=6.3.0.7
Event History
Jul 14, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1181?
CVE-2017-1181 has a medium severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2017-1181?
To fix CVE-2017-1181, ensure that all console connections for IBM Tivoli Monitoring are encrypted.
3
Which versions of IBM Tivoli Monitoring are affected by CVE-2017-1181?
CVE-2017-1181 affects IBM Tivoli Monitoring versions 6.2.2.9, 6.2.3.5, and 6.3.0.7.
4
Can CVE-2017-1181 be exploited remotely?
CVE-2017-1181 cannot be exploited remotely as it requires local access to the system.
5
What type of attack does CVE-2017-1181 enable?
CVE-2017-1181 enables a local attacker to gain elevated privileges within the IBM Tivoli Monitoring environment.