Multiple vulnerabilities in IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library



Risk Medium
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2024-28098
CVE-2024-29834
CWE-ID CWE-284
CWE-285
Exploitation vector Network
Public exploit N/A
Vulnerable software
IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library
Server applications / Other server solutions

Vendor IBM Corporation

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Improper access control

EUVDB-ID: #VU87566

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-28098

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. A remote user with produce or consume permissions to modify topic-level policies, such as retention, TTL, and offloading settings.

Mitigation

Install update from vendor's website.

Vulnerable software versions

IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library: 29.0 - 39.0

CPE2.3 External links

http://www.ibm.com/support/pages/node/7161418


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Improper authorization

EUVDB-ID: #VU88111

Risk: Medium

CVSSv3.1: 4.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2024-29834

CWE-ID: CWE-285 - Improper Authorization

Exploit availability: No

Description

The vulnerability allows a remote user to escalate privileges within the application.

The vulnerability exists due to improper authorization for namespace and topic management endpoints. A remote authenticated user with produce or consume permissions can perform unauthorized operations on partitioned topics, such as unloading topics, triggering compaction, create subscriptions and update subscription properties on partitioned topics.

Mitigation

Install update from vendor's website.

Vulnerable software versions

IBM Tivoli Netcool/OMNIbus Integration – Transport Module Common Integration Library: 29.0 - 39.0

CPE2.3 External links

http://www.ibm.com/support/pages/node/7161418


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###