cbcvebase.

Ibm Tivoli Provisioning Manager Os Deployment vulnerabilities

4 known vulnerabilities affecting ibm/tivoli_provisioning_manager_os_deployment.

Total CVEs
4
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2

Vulnerabilities

Page 1 of 1
CVE-2007-1868P2CRITICALCVSS 10.0PoCv5.1.0.1162007-04-04
CVE-2007-1868 [CRITICAL] CVE-2007-1868: The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 do The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
nvd
CVE-2008-0401P3CRITICALCVSS 10.0≤ 5.1.0.22008-01-23
CVE-2008-0401 [CRITICAL] CWE-119 CVE-2008-0401: Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager f Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.
nvd
CVE-2010-4121P3HIGHCVSS 7.5v7.1.1.32010-10-28
CVE-2010-4121 [HIGH] CWE-287 CVE-2010-4121: The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not requir The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protec
nvd
CVE-2007-3268P4HIGHCVSS 7.5v5.1.0.22007-07-18
CVE-2007-3268 [HIGH] CWE-369 CVE-2007-3268: The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 a The TFTP implementation in IBM Tivoli Provisioning Manager for OS Deployment 5.1 before Fix Pack 3 allows remote attackers to cause a denial of service (rembo.exe crash and multiple service outage) via a read (RRQ) request with an invalid blksize (blocksize), which triggers a divide-by-zero error.
nvd
Ibm Tivoli Provisioning Manager Os Deployment vulnerabilities | cvebase