Release date:
Updated on:
Affected Systems:
IBM Tivoli Monitoring 6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56809
CVE (CAN) ID: CVE-2012-3297
IBM Tivoli Monitoring is a system Monitoring software that manages operating systems, databases, and servers in distributed and host environments.
IBM Tivoli Monitoring 6.2.2 and 6.2.3 do not properly filter HTTP service console data, that is, they are returned to users and can be used to execute arbitrary HTML and script code in the affected site browser session.
<* Source: IBM (ncsupp@ca.ibm.com)
Link: http://secunia.com/advisories/51509/
Http://www-01.ibm.com/support/docview.wss? Uid = swg21618972
*>
Suggestion:
--------------------------------------------------------------------------------
Temporary solution:
If you cannot install or upgrade the patch immediately, NSFOCUS recommends that you take the following measures to reduce the threat:
Disable the HTTP server by attaching HTTP_SERVER: N to KDC_TRANSPORT. For specific methods, see: http://www-01.ibm.com/support/docview.wss? Uid = swg21422918
After the task is completed, immediately exit the Service Console session and no longer use the active Service Console browser to navigate to other websites.
Vendor patch:
IBM
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www-01.ibm.com/support/docview.wss? Uid = swg24032092
Http://www-01.ibm.com/support/docview.wss? Uid = swg24032067