APP: IBM Tivoli Monitoring Express Universal Agent Buffer Overflow

This signature detects attempts to exploit a known vulnerability against IBM Tivoli Monitoring Express. A successful attack can lead to arbitrary code execution.

Extended Description

IBM Tivoli Monitoring Express Universal Agent is prone to multiple buffer-overflow vulnerabilities because the application fails to bounds-check user-supplied data before copying it into an insufficiently sized memory buffer. An attacker can exploit these issues to execute arbitrary code within the context of the vulnerable application. This may facilitate the compromise of affected servers. To leverage these issues, the attacker does not need to authenticate. IBM Tivoli Monitoring Express 6.1 is affected.

Affected Products

Ibm tivoli_monitoring_express

References

BugTraq: 23558

CVE: CVE-2007-2137

Short Name
APP:IBM:TME-AGENT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Agent Buffer CVE-2007-2137 Express IBM Monitoring Overflow Tivoli Universal bid:23558
Release Date
10/06/2010
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3336
Port
TCP/1918,6014,10110,14206,18302
False Positive
Unknown
Vendors

Ibm

CVSS Score

10.0

Found a potential security threat?