Risk | High |
Patch available | YES |
Number of vulnerabilities | 8 |
CVE-ID | CVE-2009-4521 CVE-2015-0250 CVE-2017-5662 CVE-2018-8013 CVE-2019-17566 CVE-2020-11987 CVE-2009-4269 CVE-2021-41033 |
CWE-ID | CWE-79 CWE-20 CWE-611 CWE-502 CWE-918 CWE-310 CWE-300 |
Exploitation vector | Network |
Public exploit | Public exploit code for vulnerability #1 is available. |
Vulnerable software Subscribe |
IBM Tivoli Network Manager (ITNM) Client/Desktop applications / Software for system administration |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains information about 8 vulnerabilities.
EUVDB-ID: #VU80940
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2009-4521
CWE-ID:
Exploit availability:
DescriptionVulnerability allows a remote attacker to perform XSS attacks.
The vulnerability is caused by an input validation error in birt-viewer/run in Eclipse Business Intelligence and Reporting Tools (BIRT) before 2.5.0, as used in KonaKart and other products, when processing __report parameter. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in victim's browser in security context of vulnerable website.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU78255
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2015-0250
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows remote attackers to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can read arbitrary files or cause a denial of service via a crafted SVG file.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13180
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2017-5662
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote unauthenticated attacker to conduct XXE-attack on the target system.
The weakness exists due to improper restriction of XML external entity references. A remote attacker can supply specially crafted xml document to gain access to arbitrary files or conduct amplification attack to cause the service to crash.
Install update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU13059
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2018-8013
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient validation of user-supplied data. A remote attacker can supply specially crafted data, trigger a deserialization error in a subclass of 'AbstractDocuent' and access potentially sensitive information.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU29068
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2019-17566
CWE-ID:
Exploit availability:
DescriptionThe disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of "xlink:href" attributes. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU52501
Risk: Medium
CVSSv3.1:
CVE-ID: CVE-2020-11987
CWE-ID:
Exploit availability:
DescriptionThe disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems.
Successful exploitation of this vulnerability may allow a remote attacker gain access to sensitive data, located in the local network or send malicious requests to other servers from the vulnerable system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU77169
Risk: Low
CVSSv3.1:
CVE-ID: CVE-2009-4269
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby performs a transformation that reduces the size of the set of inputs to SHA-1. A local attacker can gain unauthorized access to sensitive information on the system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?
EUVDB-ID: #VU80939
Risk: High
CVSSv3.1:
CVE-ID: CVE-2021-41033
CWE-ID:
Exploit availability:
DescriptionThe vulnerability allows a remote attacker to perform Man-in-the-Middle (MitM) attack.
The vulnerability exists if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local installation. A remote unauthenticated attacker can perform Man-in-the-Middle (MitM) attack.
MitigationInstall update from vendor's website.
Vulnerable software versionsIBM Tivoli Network Manager (ITNM): before 4.2.0.16
Fixed software versionsCPE2.3 External links
http://www.ibm.com/support/pages/node/6852611
Q & A
Can this vulnerability be exploited remotely?
Is there known malware, which exploits this vulnerability?