IBM Security Bulletin: IBM Tivoli Monitoring is affected by a vulnerability in its internal web server

A vulnerability exists in the internal web server provided by IBM Tivoli Monitoring basic services. It could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error. A remote attacker could exploit this vulnerability to execute arbitrary code on the system or cause the application to crash.

CVE(s): CVE-2017-1635

Affected product(s) and affected version(s):

The KDH component of IBM Tivoli Monitoring Basic Services (KGL,KAX) for Version 6.2.2 through 6.2.2 Fix Pack 9

Refer to the following reference URLs for remediation and additional vulnerability details:
Source Bulletin: http://ift.tt/2hB214M
X-Force Database: http://ift.tt/2zQpR7i

The post IBM Security Bulletin: IBM Tivoli Monitoring is affected by a vulnerability in its internal web server appeared first on IBM PSIRT Blog.



from IBM Product Security Incident Response Team http://ift.tt/2hAZ6ZW