Remote Code Execution Vulnerability in IBM Tivoli Endpoint Manager Mobile Device Management
CVE-2014-6140

Currently unrated

Key Information:

Vendor
IBM
Vendor
CVE Published:
6 December 2014

Summary

IBM Tivoli Endpoint Manager Mobile Device Management prior to version 9.0.60100 is susceptible to a remote code execution vulnerability due to the use of a common HMAC token across multiple customer installations. This flaw enables attackers to exploit crafted marshalled Ruby objects within cookies, potentially leading to arbitrary code execution in various components including the Enrollment and Apple iOS Management Extender, Self-service portal, Trusted Services provider, and the Admin Portal.

References

EPSS Score

9% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.