Ibm Tivoli Monitoring vulnerabilities
29 known vulnerabilities affecting ibm/tivoli_monitoring.
Total CVEs
29
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH11MEDIUM8
Vulnerabilities
Page 1 of 2
CVE-2025-3356CRITICALCVSS 9.8v6.3.0.7≥ 6.3.0.7, ≤ 6.3.0.7 Service Pack 212025-10-30
CVE-2025-3356 [HIGH] CWE-22 CVE-2025-3356: IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to trave
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view, overwrite, or append to arbitrary files on the system.
cvelistv5nvd
CVE-2025-3355HIGHCVSS 7.5v6.3.0.7≥ 6.3.0.7, ≤ 6.3.0.7 Service Pack 212025-10-30
CVE-2025-3355 [HIGH] CWE-22 CVE-2025-3355: IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to trave
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
cvelistv5nvd
CVE-2025-3320CRITICALCVSS 9.8v6.3.0.7≥ 6.3.0.7, ≤ 6.3.0.7 SP202025-08-06
CVE-2025-3320 [HIGH] CWE-122 CVE-2025-3320: IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer o
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
cvelistv5nvd
CVE-2025-3354CRITICALCVSS 9.8v6.3.0.7≥ 6.3.0.7, ≤ 6.3.0.7 SP202025-08-06
CVE-2025-3354 [HIGH] CWE-122 CVE-2025-3354: IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer o
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 20 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
cvelistv5nvd
CVE-2025-3357CRITICALCVSS 9.8v6.3.0.7≥ 6.3.0.7, ≤ 6.3.0.7 SP152025-05-28
CVE-2025-3357 [CRITICAL] CWE-1285 CVE-2025-3357: IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execu
IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array.
cvelistv5nvd
CVE-2020-4311HIGHCVSS 7.0v6.3.02020-04-23
CVE-2020-4311 [HIGH] CWE-732 CVE-2020-4311: IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By
IBM Tivoli Monitoring 6.3.0 could allow a local attacker to execute arbitrary code on the system. By placing a specially crafted file, an attacker could exploit this vulnerability to load other DLL files located in the same directory and execute arbitrary code on the system. IBM X-Force ID: 177083.
cvelistv5nvd
CVE-2019-4592HIGHCVSS 7.5≥ 6.3.0.7.3, ≤ 6.3.0.7.10v6.3.0.7.3+1 more2020-02-13
CVE-2019-4592 [HIGH] CVE-2019-4592: IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to acces
IBM Tivoli Monitoring Service 6.3.0.7.3 through 6.3.0.7.10 could allow an unauthorized user to access and modify operation aspects of the ITM monitoring server possibly leading to an effective denial of service or disabling of the monitoring server. IBM X-Force ID: 167647.
cvelistv5nvd
CVE-2017-1794HIGHCVSS 7.5≥ 6.2.3, ≤ 6.2.3.5≥ 6.3.0, ≤ 6.3.0.7+14 more2018-09-19
CVE-2017-1794 [HIGH] CWE-400 CVE-2017-1794: IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS us
IBM Tivoli Monitoring 6.2.3 through 6.2.3.5 and 6.3.0 through 6.3.0.7 are vulnerable to both TEPS user privilege escalation and possible denial of service due to unconstrained memory growth. IBM X-Force ID: 137039.
cvelistv5nvd
CVE-2017-1789CRITICALCVSS 9.8v6.2.3v6.2.3.1+12 more2018-03-22
CVE-2017-1789 [CRITICAL] CWE-94 CVE-2017-1789: IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute cod
IBM Tivoli Monitoring V6 6.2.3 and 6.3.0 could allow an unauthenticated user to remotely execute code through unspecified methods. IBM X-Force ID: 137034.
nvd
CVE-2017-1635HIGHCVSS 8.0v6.2.2v6.2.2.2+7 more2017-12-13
CVE-2017-1635 [HIGH] CWE-416 CVE-2017-1635: IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the syst
IBM Tivoli Monitoring V6 6.2.2.x could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash. IBM X-Force ID: 133243.
nvd
CVE-2017-1183HIGHCVSS 7.5v6.2.2.9v6.2.3.5+1 more2017-07-17
CVE-2017-1183 [HIGH] CWE-89 CVE-2017-1183: IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL comman
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.
nvd
CVE-2017-1182HIGHCVSS 7.5v6.2.2.9v6.2.3.5+1 more2017-07-17
CVE-2017-1182 [HIGH] CVE-2017-1182: IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.
nvd
CVE-2017-1181HIGHCVSS 7.0v6.2.2.9v6.2.3.5+1 more2017-07-17
CVE-2017-1181 [HIGH] CWE-319 CVE-2017-1181: IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.
nvd
CVE-2016-6083MEDIUMCVSS 5.3v6.2.2v6.2.2.0+24 more2017-06-27
CVE-2016-6083 [MEDIUM] CWE-200 CVE-2016-6083: IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could conta
IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.
nvd
CVE-2016-5933MEDIUMCVSS 4.6v6.2.2v6.2.2.2+21 more2017-03-08
CVE-2016-5933 [MEDIUM] CWE-254 CVE-2016-5933: IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223.
nvd
CVE-2016-2946HIGHCVSS 7.8v6.2.2v6.2.2.1+10 more2016-12-01
CVE-2016-2946 [HIGH] CWE-119 CVE-2016-2946: Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6
Stack-based buffer overflow in the ax Shared Libraries in the Agent in IBM Tivoli Monitoring (ITM) 6.2.2 before FP9, 6.2.3 before FP5, and 6.3.0 before FP2 on Linux and UNIX allows local users to gain privileges via unspecified vectors.
nvd
CVE-2015-7411CRITICALCVSS 9.9v6.2.2v6.2.2.1+10 more2016-03-12
CVE-2015-7411 [CRITICAL] CWE-264 CVE-2015-7411: The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 thr
The portal client in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 through FP6 allows remote authenticated users to gain privileges via unspecified vectors.
nvd
CVE-2015-5003HIGHCVSS 8.5v6.2.2v6.2.3+1 more2016-01-03
CVE-2015-5003 [HIGH] CWE-77 CVE-2015-5003: The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7
The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing crafted input.
nvd
CVE-2014-6141HIGHCVSS 8.5v6.2.0v6.2.0.1+31 more2015-02-02
CVE-2014-6141 [HIGH] CWE-264 CVE-2014-6141: IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 throug
IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.
nvd
CVE-2013-0551MEDIUMCVSS 5.0v6.2.0v6.2.0.1+20 more2013-06-21
CVE-2013-0551 [MEDIUM] CWE-20 CVE-2013-0551: The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.
The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service
nvd
1 / 2Next →