Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-6140

Опубликовано: 06 дек. 2014
Источник: nvd
CVSS2: 9.3
EPSS Низкий

Описание

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ibm:tivoli_endpoint_manager_mobile_device_management:*:*:*:*:*:*:*:*
Версия до 9.0 (включая)

EPSS

Процентиль: 93%
0.09339
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-310

Связанные уязвимости

github
больше 3 лет назад

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.

EPSS

Процентиль: 93%
0.09339
Низкий

9.3 Critical

CVSS2

Дефекты

CWE-310