CVE-2007-1868

IBM Tivoli Provisioning Manager OS Deployment - Denial of Service

Title source: rule

Description

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16810
metasploit WORKING POC GOOD
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/ibm_tpmfosd_overflow.rb

Scores

EPSS 0.7713
EPSS Percentile 99.0%

Details

Status published
Products (1)
ibm/tivoli_provisioning_manager_os_deployment 5.1.0.116
Published Apr 04, 2007
Tracked Since Feb 18, 2026