Vulnerability Name: | CVE-2008-5686 (CCN-47307) | ||||||||
Assigned: | 2008-12-12 | ||||||||
Published: | 2008-12-12 | ||||||||
Updated: | 2011-03-08 | ||||||||
Summary: | IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 8.5 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C) 6.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.0 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Bypass Security | ||||||||
References: | Source: MITRE Type: CNA CVE-2008-5686 Source: CCN Type: SA33143 IBM Tivoli Provisioning Manager SOAP Authentication Security Issue Source: SECUNIA Type: Vendor Advisory 33143 Source: CCN Type: SECTRACK ID: 1021394 IBM Tivoli Provisioning Manager LDAP Access Control Bug Lets Remote Users Execute SOAP Commands Source: SECTRACK Type: UNKNOWN 1021394 Source: CCN Type: IBM Support & downloads SOAP authentication vulnerability Source: CONFIRM Type: Patch, Vendor Advisory http://www-01.ibm.com/support/docview.wss?uid=swg21330228 Source: CCN Type: OSVDB ID: 52604 IBM Tivoli Provisioning Manager (TPM) LDAP Bypass Arbitrary SOAP Command TPM Functionality Access Source: BID Type: UNKNOWN 32824 Source: CCN Type: BID-32824 IBM Tivoli Provisioning Manager Security Bypass Vulnerability Source: VUPEN Type: UNKNOWN ADV-2008-3432 Source: XF Type: UNKNOWN tpm-soap-security-bypass(47307) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |