IBM Security Bulletin: A vulnerability in the SQLite component of the Response Time agent affects IBM Performance Management products (CVE-2016-6153)
May 9, 2017 10:00 am EDT
Categorized: Medium Severity
SQLite could allow a local attacker to gain elevated privileges on the system, caused by the creation of temporary files in directory with insecure permissions. An attacker could exploit this vulnerability to obtain leaked data.
CVE(s): CVE-2016-6153
Affected product(s) and affected version(s):
IBM Monitoring 8.1.3
IBM Application Performance Management 8.1.3
IBM Application Performance Management Advanced 8.1.3
IBM Cloud Application Performance Management
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2pYmg1n
X-Force Database: http://ift.tt/2fVEdaJ
from IBM Product Security Incident Response Team http://ift.tt/2pYfV67