Ibm Tivoli Monitoring vulnerabilities
29 known vulnerabilities affecting ibm/tivoli_monitoring.
Total CVEs
29
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH11MEDIUM8
Vulnerabilities
Page 2 of 2
CVE-2017-1181P4HIGHCVSS 7.0v6.2.2.9v6.2.3.5+1 more2017-07-17
CVE-2017-1181 [HIGH] CWE-319 CVE-2017-1181: IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for
IBM Tivoli Monitoring Portal V6 client could allow a local attacker to gain elevated privileges for IBM Tivoli Monitoring, caused by the default console connection not being encrypted. IBM X-Force ID: 123487.
nvd
CVE-2016-6083P4MEDIUMCVSS 5.3v6.2.2v6.2.2.0+24 more2017-06-27
CVE-2016-6083 [MEDIUM] CWE-200 CVE-2016-6083: IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could conta
IBM Tivoli Monitoring V6 could allow an unauthenticated user to access SOAP queries that could contain sensitive information. IBM X-Force ID: 117696.
nvd
CVE-2013-2960P4MEDIUMCVSS 5.0v6.2.0v6.2.0.1+20 more2013-06-21
CVE-2013-2960 [MEDIUM] CWE-119 CVE-2013-2960: Buffer overflow in KDSMAIN in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 thro
Buffer overflow in KDSMAIN in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attacker
nvd
CVE-2013-2961P4MEDIUMCVSS 4.3v6.2.0v6.2.0.1+20 more2013-06-21
CVE-2013-2961 [MEDIUM] CWE-20 CVE-2013-2961: The internal web server in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through
The internal web server in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to
nvd
CVE-2013-0551P4MEDIUMCVSS 5.0v6.2.0v6.2.0.1+20 more2013-06-21
CVE-2013-0551 [MEDIUM] CWE-20 CVE-2013-0551: The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.
The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service
nvd
CVE-2013-0548P4MEDIUMCVSS 4.3v6.2.0v6.2.0.1+20 more2013-06-21
CVE-2013-0548 [MEDIUM] CWE-79 CVE-2013-0548: Multiple cross-site scripting (XSS) vulnerabilities in the Basic Services component in IBM Tivoli Mo
Multiple cross-site scripting (XSS) vulnerabilities in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products
nvd
CVE-2016-5933P4MEDIUMCVSS 4.6v6.2.2v6.2.2.2+21 more2017-03-08
CVE-2016-5933 [MEDIUM] CWE-254 CVE-2016-5933: IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223.
nvd
CVE-2013-0576P4MEDIUMCVSS 4.3v6.2.0v6.2.0.1+20 more2013-05-28
CVE-2013-0576 [MEDIUM] CWE-79 CVE-2013-0576: Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivol
Cross-site scripting (XSS) vulnerability in the Tivoli Enterprise Portal browser client in IBM Tivoli Monitoring 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP02 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2012-3297P4MEDIUMCVSS 4.3v6.2.2v6.2.32012-12-08
CVE-2012-3297 [MEDIUM] CWE-79 CVE-2012-3297: Cross-site scripting (XSS) vulnerability in the embedded HTTP server in the Service Console in IBM T
Cross-site scripting (XSS) vulnerability in the embedded HTTP server in the Service Console in IBM Tivoli Monitoring 6.2.2 before 6.2.2-TIV-ITM-FP0009 and 6.3.2 before 6.2.3-TIV-ITM-FP0001 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
nvd
← Previous2 / 2