Required CVE Record Information
Description
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
References 7 Total
- vupen.com: ADV-2007-1199 vdb-entry
- labs.idefense.com: 20070331 IBM Tivoli Provisioning Manager for OS Deployment Multiple Vulnerabilities third-party-advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg24015347
- securityfocus.com: 23264 vdb-entry
- secunia.com: 24717 third-party-advisory
- exchange.xforce.ibmcloud.com: tivoli-post-code-execution(33384) vdb-entry
- securitytracker.com: 1017840 vdb-entry
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- vupen.com: ADV-2007-1199 vdb-entryx_transferred
- labs.idefense.com: 20070331 IBM Tivoli Provisioning Manager for OS Deployment Multiple Vulnerabilities third-party-advisoryx_transferred
- http://www-1.ibm.com/support/docview.wss?uid=swg24015347 x_transferred
- securityfocus.com: 23264 vdb-entryx_transferred
- secunia.com: 24717 third-party-advisoryx_transferred
- exchange.xforce.ibmcloud.com: tivoli-post-code-execution(33384) vdb-entryx_transferred
- securitytracker.com: 1017840 vdb-entryx_transferred