Remote Code Execution Vulnerability in IBM Tivoli Endpoint Manager Mobile Device Management
CVE-2014-6140
Currently unrated
Key Information:
- Vendor
- IBM
- Vendor
- CVE Published:
- 6 December 2014
Summary
IBM Tivoli Endpoint Manager Mobile Device Management prior to version 9.0.60100 is susceptible to a remote code execution vulnerability due to the use of a common HMAC token across multiple customer installations. This flaw enables attackers to exploit crafted marshalled Ruby objects within cookies, potentially leading to arbitrary code execution in various components including the Enrollment and Apple iOS Management Extender, Self-service portal, Trusted Services provider, and the Admin Portal.
References
EPSS Score
9% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved