Remote Code Execution Vulnerability in IBM Tivoli Endpoint Manager Mobile Device Management
CVE-2014-6140
Currently unrated
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 6 December 2014
What is CVE-2014-6140?
IBM Tivoli Endpoint Manager Mobile Device Management prior to version 9.0.60100 is susceptible to a remote code execution vulnerability due to the use of a common HMAC token across multiple customer installations. This flaw enables attackers to exploit crafted marshalled Ruby objects within cookies, potentially leading to arbitrary code execution in various components including the Enrollment and Apple iOS Management Extender, Self-service portal, Trusted Services provider, and the Admin Portal.