Description
IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows.
References (5)
Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/32824
Third Party Advisory vdb-entry
x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3432
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://securitytracker.com/id?1021394
Vendor Advisory third-party-advisory
x_refsource_secunia
http://secunia.com/advisories/33143
Patch, Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21330228
Scores
EPSS
0.0214
EPSS Percentile
79.8%
Details
CWE
CWE-287
Status
published
Products (4)
ibm/tivoli_provisioning_manager
5.1
ibm/tivoli_provisioning_manager
5.1.0.2
ibm/tivoli_provisioning_manager
5.1.1
ibm/tivoli_provisioning_manager
5.1.1.1
Published
Dec 19, 2008
Tracked Since
Feb 18, 2026