IBM Security Bulletin: IBM Tivoli Monitoring TEP Server vulnerabilities

By default, communications between the Tivoli Enterprise Portal client and server are not encrypted which can cause the following vulnerabilities.

CVE(s): CVE-2017-1181, CVE-2017-1183, CVE-2017-1182

Affected product(s) and affected version(s):

IBM Tivoli Portal Server (KCQ component) versions 6.2.2 Fix Pack 9, 6.2.3 through 6.2.3 Fix Pack 5 and 6.3.0 through 6.3.0 Fix Pack 7

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2umFfWK
X-Force Database: http://ift.tt/2uVel5x
X-Force Database: http://ift.tt/2umwf3X
X-Force Database: http://ift.tt/2uV17pn

The post IBM Security Bulletin: IBM Tivoli Monitoring TEP Server vulnerabilities appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2umDY28