IBM Security Bulletin: IBM Tivoli Monitoring Buffer Overflow (CVE-2016-2946 )

A utility shipped as part of the IBM Tivoli Monitoring (ITM) Shared Libraries (“ax” component) is subject to a buffer overflow.

CVE(s): CVE-2016-2946

Affected product(s) and affected version(s):

The Shared Libraries (“ax” component) versions 6.2.2 through 6.3.0 FP1 on UNIX and Linux are affected. The Shared Libraries are shipped as part of all ITM components including servers (e.g. portal server, monitoring server) as well as all ITM agents (e.g. OS Agents, Agentless Agents, ITCAM Agents)

The shared libraries on Windows (“GL” component) is not affected on any supported versions.

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2bguxVC
X-Force Database: http://ift.tt/2b5AUhZ



from IBM Product Security Incident Response Team http://ift.tt/2bgtJQD