IBM Tivoli System Automation Application Manager Multiple Vulnerabilities
RISK: High Risk
TYPE: Servers - Network Management
Multiple vulnerabilities have been identified in IBM Tivoli System Automation Application Manager, which can be exploited by malicious, local users to disclose potentially sensitive information, manipulate certain data, and cause a DoS (Denial of Service), by malicious users to bypass certain security restrictions, and by malicious people to conduct spoofing and cross-site scripting attacks, disclose potentially sensitive information, manipulate certain data, cause a DoS (Denial of Service), and compromise a vulnerable system.
Impact
- Cross-Site Scripting
- Denial of Service
- Remote Code Execution
- Security Restriction Bypass
- Information Disclosure
- Spoofing
System / Technologies affected
- IBM Tivoli System Automation Application Manager 3.x
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- Update to version 3.2.2.1
Vulnerability Identifier
- CVE-2011-3563
- CVE-2012-0497
- CVE-2012-0498
- CVE-2012-0499
- CVE-2012-0501
- CVE-2012-0502
- CVE-2012-0503
- CVE-2012-0505
- CVE-2012-0506
- CVE-2012-0507
- CVE-2012-1713
- CVE-2012-1716
- CVE-2012-1717
- CVE-2012-1718
- CVE-2012-1719
- CVE-2012-1720
- CVE-2012-1721
- CVE-2012-1722
- CVE-2012-1725
- CVE-2012-3325
Source
Related Link
Share with