IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.
2017-07-17T13:18:22.047
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 7.5 (HIGH)
AV:A/AC:M/Au:N/C:P/I:P/A:P
5.5
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | tivoli_monitoring | 6.2.2.9 | Yes |
Application | ibm | tivoli_monitoring | 6.2.3.5 | Yes |
Application | ibm | tivoli_monitoring | 6.3.0.7 | Yes |