Remote Code Execution Vulnerability in IBM Tivoli Endpoint Manager Mobile Device Management
CVE-2014-6140
Key Information:
- Vendor
IBM
- Vendor
- CVE Published:
- 6 December 2014
What is CVE-2014-6140?
IBM Tivoli Endpoint Manager Mobile Device Management prior to version 9.0.60100 is susceptible to a remote code execution vulnerability due to the use of a common HMAC token across multiple customer installations. This flaw enables attackers to exploit crafted marshalled Ruby objects within cookies, potentially leading to arbitrary code execution in various components including the Enrollment and Apple iOS Management Extender, Self-service portal, Trusted Services provider, and the Admin Portal.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
9% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved