cbcvebase.
CVE-2017-1182
published 2017-07-17

CVE-2017-1182: IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default…

PriorityP274high7.5CVSS 3.0
AVAACHPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
8.54%
94.4th percentile
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.

Affected

6 ranges
VendorProductVersion rangeFixed in
ibmtivoli_monitoring
ibmtivoli_monitoring
ibmtivoli_monitoring
ibmtivoli_monitoring_v6
ibmtivoli_monitoring_v6
ibmtivoli_monitoring_v6

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2017-1182 affects IBM Tivoli Monitoring Portal v6 and is exploitable by a local (network adjacent) attacker when default HTTP client-server communications are in use — monitor for unexpected command execution originating from HTTP-based Tivoli Monitoring Portal traffic on the network segment.
  • ·The vulnerability is only exploitable when the IBM Tivoli Monitoring Portal v6 is configured to use the default HTTP (not HTTPS) client-server communication channel; deployments using encrypted/non-default transport may not be exposed.

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.