CVE-2017-1794: High severity ibm tivoli monitoring vulnerability
Published Sep 19, 2018
·Updated
IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039.
Affected Software
2 affected components
IBM Tivoli Monitoring>=6.2.3<=6.2.3.5
IBM Tivoli Monitoring>=6.3.0<=6.3.0.7
Event History
Sep 19, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-1794?
The severity of CVE-2017-1794 is considered high due to the potential for privilege escalation and denial of service.
2
How do I fix CVE-2017-1794?
To fix CVE-2017-1794, update IBM Tivoli Monitoring to a version later than 6.2.3.5 or 6.3.0.7.
3
What versions of IBM Tivoli Monitoring are affected by CVE-2017-1794?
IBM Tivoli Monitoring versions 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are affected by CVE-2017-1794.
4
What kind of attack can CVE-2017-1794 enable?
CVE-2017-1794 can enable user privilege escalation as well as a potential denial of service attack.
5
Is there a workaround for CVE-2017-1794?
There are no known effective workarounds for CVE-2017-1794, so applying the relevant updates is essential.