CVE-2017-1183: SQL Injection
Published Jul 14, 2017
·Updated
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.
Affected Software
3 affected components
IBM Tivoli Monitoring=6.2.2.9
IBM Tivoli Monitoring=6.2.3.5
IBM Tivoli Monitoring=6.3.0.7
Remediation
Patch Available
Event History
Jul 14, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1183?
CVE-2017-1183 has a medium severity rating, allowing local attackers to modify SQL commands.
2
How do I fix CVE-2017-1183?
To mitigate CVE-2017-1183, it is recommended to update to a non-vulnerable version of IBM Tivoli Monitoring.
3
Who is affected by CVE-2017-1183?
CVE-2017-1183 affects IBM Tivoli Monitoring versions 6.2.2.9, 6.2.3.5, and 6.3.0.7.
4
What type of attack does CVE-2017-1183 facilitate?
CVE-2017-1183 facilitates local network adjacent attackers in modifying SQL commands sent to the Portal Server.
5
Is CVE-2017-1183 applicable in all installations of IBM Tivoli Monitoring?
CVE-2017-1183 is applicable only in installations using default HTTP communication settings.