Lucene search

K
ibmIBMAD451DAE200F4A46686ED7A0FE36F67961972806FA8AE46B77B3F4F2CC99992A
HistoryJun 17, 2018 - 3:45 p.m.

Security Bulletin: Vulnerability in the libcURL component of Tivoli Netcool/OMNIbus (CVE-2017-1000100)

2018-06-1715:45:24
www.ibm.com
14

0.004 Low

EPSS

Percentile

73.2%

Summary

Vulnerability has been addressed in the libcURL component of Tivoli Netcool/OMNIbus.

Vulnerability Details

CVEID: CVE-2017-1000100**
DESCRIPTION:** cURL could allow a remote attacker to obtain sensitive information, caused by a TFTP URL Processing flaw. By sending a specially-crafted request, an attacker could exploit this vulnerability to obtain sensitive information.
CVSS Base Score: 7.5
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/130190 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

Tivoli Netcool/OMNIbus 8.1.0, Tivoli Netcool/OMNIbus 7.4.0

Remediation/Fixes

Product

| VRMF| APAR| Remediation/First Fix
β€”|β€”|β€”|β€”
OMNIbus| 7.4.0.16| IV99760| http://www-01.ibm.com/support/docview.wss?uid=swg24044022
OMNIbus| 8.1.0.15| IV99760| <http://www-01.ibm.com/support/docview.wss?uid=swg24044023&gt;

Workarounds and Mitigations

None