{"api_version":"1","generated_at":"2026-07-23T10:13:36+00:00","cve":"CVE-2008-5686","urls":{"html":"https://cve.report/CVE-2008-5686","api":"https://cve.report/api/cve/CVE-2008-5686.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-5686","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-5686"},"summary":{"title":"CVE-2008-5686","description":"IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-12-19 17:30:03","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"8.5","severity":"","vector":"AV:N/AC:M/Au:S/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21330228","name":"http://www-01.ibm.com/support/docview.wss?uid=swg21330228","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"IBM notice: The page you requested cannot be displayed","mime":"text/html","httpstatus":"404","archivestatus":"410"},{"url":"http://www.vupen.com/english/advisories/2008/3432","name":"http://www.vupen.com/english/advisories/2008/3432","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/33143","name":"http://secunia.com/advisories/33143","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"IBM Tivoli Provisioning Manager SOAP Authentication Security Issue - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/32824","name":"http://www.securityfocus.com/bid/32824","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Tivoli Provisioning Manager Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1021394","name":"http://securitytracker.com/id?1021394","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM Tivoli Provisioning Manager LDAP Access Control Bug Lets Remote Users Execute SOAP Commands - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-5686","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-5686","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"5686","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_provisioning_manager","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5686","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_provisioning_manager","cpe6":"5.1.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5686","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_provisioning_manager","cpe6":"5.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2008","cve_id":"5686","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ibm","cpe5":"tivoli_provisioning_manager","cpe6":"5.1.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T11:04:44.173Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"32824","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/32824"},{"name":"ADV-2008-3432","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/3432"},{"name":"1021394","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1021394"},{"name":"33143","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/33143"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21330228"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-12-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-12-30T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"32824","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/32824"},{"name":"ADV-2008-3432","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/3432"},{"name":"1021394","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1021394"},{"name":"33143","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/33143"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-01.ibm.com/support/docview.wss?uid=swg21330228"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-5686","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"32824","refsource":"BID","url":"http://www.securityfocus.com/bid/32824"},{"name":"ADV-2008-3432","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/3432"},{"name":"1021394","refsource":"SECTRACK","url":"http://securitytracker.com/id?1021394"},{"name":"33143","refsource":"SECUNIA","url":"http://secunia.com/advisories/33143"},{"name":"http://www-01.ibm.com/support/docview.wss?uid=swg21330228","refsource":"CONFIRM","url":"http://www-01.ibm.com/support/docview.wss?uid=swg21330228"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-5686","datePublished":"2008-12-19T17:00:00.000Z","dateReserved":"2008-12-19T00:00:00.000Z","dateUpdated":"2024-08-07T11:04:44.173Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-12-19 17:30:03","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:C/I:C/A:C","baseScore":8.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":6.8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_provisioning_manager:5.1:*:*:*:*:*:*:*","matchCriteriaId":"A141AB15-2D7B-4D48-9A1A-CEF50F21BEB4"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_provisioning_manager:5.1.0.2:*:*:*:*:*:*:*","matchCriteriaId":"128205D3-F6BD-47CB-B07E-B44FF7359D0D"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_provisioning_manager:5.1.1:*:*:*:*:*:*:*","matchCriteriaId":"DD89F060-05A7-46E4-A893-FBCEBC532703"},{"vulnerable":true,"criteria":"cpe:2.3:a:ibm:tivoli_provisioning_manager:5.1.1.1:*:*:*:*:*:*:*","matchCriteriaId":"4DD76DD8-85B6-4D1E-BCA3-996A70CBE570"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"5686","Ordinal":"1","Title":"CVE-2008-5686","CVE":"CVE-2008-5686","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"5686","Ordinal":"1","NoteData":"IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows.","Type":"Description","Title":"CVE-2008-5686"},{"CveYear":"2008","CveId":"5686","Ordinal":"2","NoteData":"2008-12-19","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"5686","Ordinal":"3","NoteData":"2008-12-30","Type":"Other","Title":"Modified"}]}}}