Lucene search

K
ibmIBM9D4049943D1946AB71B0B67E00156CDC1CEC43E9122B86B9DC13C2A879764A86
HistoryNov 03, 2020 - 2:07 a.m.

Security Bulletin: Multiple vulnerabilities have been identified in IBM Tivoli Netcool/OMNIbus Gateway for SNMP (CVE-2020-15861, CVE-2020-15862)

2020-11-0302:07:52
www.ibm.com
12
ibm tivoli netcool
snmp gateway
vulnerabilities
net-snmp
cve-2020-15861
cve-2020-15862
elevated privileges
improper privilege management
snmp write access
ibm tivoli netcool omnibus/gateway for snmp
nco-g-snmp-7_0
nco-g-snmp-8_0

EPSS

0

Percentile

14.2%

Summary

Netcool/OMNIbus SNMP Gateway is vulnerable to the weaknesses in Net-SNMP library. (CVE-2020-15861, CVE-2020-15862)

Vulnerability Details

CVEID:CVE-2020-15861
**DESCRIPTION:**Net-SNMP could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper handling of symlinks by snmpd. By using a specially-crafted symbolic link, an authenticated attacker could exploit this vulnerability to gain elevated privileges.
CVSS Base score: 7.8
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187031 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)

CVEID:CVE-2020-15862
**DESCRIPTION:**Net-SNMP could allow a local authenticated attacker to gain elevated privileges on the system, caused by an improper privilege management flaw related to SNMP WRITE access to the EXTEND MIB. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to execute arbitrary commands on the system with root privileges.
CVSS Base score: 6.7
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/187034 for the current score.
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)
IBM Tivoli Netcool OMNIbus/Gateway for SNMP nco-g-snmp-7_0 and earlier

Remediation/Fixes

Product(s) Release Note(s)
IBM Tivoli Netcool OMNIbus/Gateway for SNMP

nco-g-snmp-8_0

Workarounds and Mitigations

None