PT-2017-12262 · Ibm · Ibm Tivoli Monitoring Portal

Published

2017-07-14

·

Updated

2017-07-20

·

CVE-2017-1183

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Tivoli Monitoring Portal version 6
Description The issue allows a local attacker to modify SQL commands to the Portal Server when default client-server communications over HTTP are used.
Recommendations For IBM Tivoli Monitoring Portal version 6, consider modifying the default client-server communications to use a more secure protocol or restrict access to the Portal Server to minimize the risk of exploitation.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-1183

Affected Products

Ibm Tivoli Monitoring Portal