IBM Tivoli Provisioning Manager Security Bypass Vulnerability
BID:32824
Info
IBM Tivoli Provisioning Manager Security Bypass Vulnerability
| Bugtraq ID: | 32824 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 12 2008 12:00AM |
| Updated: | Dec 18 2008 04:21PM |
| Credit: | IBM |
| Vulnerable: |
IBM Tivoli Provisioning Manager 5.1.1 IBM Tivoli Provisioning Manager 5.1.1.1 IBM Tivoli Provisioning Manager 5.1.0.2 |
| Not Vulnerable: | |
Discussion
IBM Tivoli Provisioning Manager Security Bypass Vulnerability
IBM Tivoli Provisioning Manager is prone to an unspecified security-bypass vulnerability.
Attackers may be able to exploit this vulnerability to bypass the SOAP authentication mechanism and run SOAP commands.
This issue affects versions prior to Tivoli Provisioning Manager 5.1.1.1 with Interim Fix IF0006 applied.
IBM Tivoli Provisioning Manager is prone to an unspecified security-bypass vulnerability.
Attackers may be able to exploit this vulnerability to bypass the SOAP authentication mechanism and run SOAP commands.
This issue affects versions prior to Tivoli Provisioning Manager 5.1.1.1 with Interim Fix IF0006 applied.
Exploit / POC
IBM Tivoli Provisioning Manager Security Bypass Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IBM Tivoli Provisioning Manager Security Bypass Vulnerability
Solution:
The vendor has released fixes; please see the references for more information.
Solution:
The vendor has released fixes; please see the references for more information.
References
IBM Tivoli Provisioning Manager Security Bypass Vulnerability
References:
References: