IBM Tivoli Monitoring SOAP Interface Insecure Configuration Remote SOAP Query Information Disclosure
Medium Nessus Plugin ID 101168
SynopsisAn application installed on the Windows host is affected by an information disclosure vulnerability.
DescriptionIBM Tivoli Monitoring, a network asset monitoring platform, is installed on the remote Windows host and is using an insecure configuration. It is, therefore, affected by an information disclosure vulnerability in the SOAP interface due to an insecure default configuration. An unauthenticated, remote attacker can exploit this to disclose SOAP queries that may contain sensitive information.
SolutionApply the interim fix or workaround per the vendor advisory.