First published: Wed Sep 19 2018(Updated: )
IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Tivoli Monitoring | >=6.2.3<=6.2.3.5 | |
IBM Tivoli Monitoring | >=6.3.0<=6.3.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-1794 is considered high due to the potential for privilege escalation and denial of service.
To fix CVE-2017-1794, update IBM Tivoli Monitoring to a version later than 6.2.3.5 or 6.3.0.7.
IBM Tivoli Monitoring versions 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are affected by CVE-2017-1794.
CVE-2017-1794 can enable user privilege escalation as well as a potential denial of service attack.
There are no known effective workarounds for CVE-2017-1794, so applying the relevant updates is essential.