IBM Security Bulletin: IBM Tivoli Monitoring TEP Server vulnerabilities
By default, communications between the Tivoli Enterprise Portal client and server are not encrypted which can cause the following vulnerabilities.
CVE(s): CVE-2017-1181, CVE-2017-1183, CVE-2017-1182
Affected product(s) and affected version(s):
IBM Tivoli Portal Server (KCQ component) versions 6.2.2 Fix Pack 9, 6.2.3 through 6.2.3 Fix Pack 5 and 6.3.0 through 6.3.0 Fix Pack 7
Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2umFfWK
X-Force Database: http://ift.tt/2uVel5x
X-Force Database: http://ift.tt/2umwf3X
X-Force Database: http://ift.tt/2uV17pn
The post IBM Security Bulletin: IBM Tivoli Monitoring TEP Server vulnerabilities appeared first on IBM PSIRT Blog.
from IBM Product Security Incident Response Team http://ift.tt/2umDY28