CVE-2014-6140

IBM Tivoli Endpoint Manager Mobile Device Management < 9.0 - Remote Code Execution via HMAC Token Cookie

Title source: llm
STIX 2.1

Description

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.

References (7)

Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1031306
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/71424
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534131/100/0/threaded
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21691701
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/3

Scores

EPSS 0.0649
EPSS Percentile 93.0%

Details

CWE
CWE-310
Status published
Products (1)
ibm/tivoli_endpoint_manager_mobile_device_management < 9.0
Published Dec 06, 2014
Tracked Since Feb 18, 2026