PT-2025-23088 · Ibm · Ibm Tivoli Monitoring
Aleksandr Tlyapov
·
Published
2025-05-28
·
Updated
2025-06-02
·
CVE-2025-3357
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Tivoli Monitoring versions 6.3.0.7 through 6.3.0.7 Service Pack 19
Description
The issue allows a remote attacker to execute arbitrary code due to improper validation of an index value of a dynamically allocated array. This can be exploited without authentication.
Recommendations
For versions 6.3.0.7 through 6.3.0.7 Service Pack 19, update to Service Pack 20 to resolve the issue. As a temporary workaround, consider restricting access to the affected system until the patch is applied.
Fix
RCE
Improper Validation of Array Index
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Tivoli Monitoring