CVE-2014-6140
IBM Tivoli Endpoint Manager Mobile Device Management < 9.0 - Remote Code Execution via HMAC Token Cookie
Title source: llmDescription
IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.
References (7)
Core 7
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_sectrack
http://www.securitytracker.com/id/1031306
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/71424
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/534131/100/0/threaded
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=swg21691701
Exploit x_refsource_misc
http://packetstormsecurity.com/files/129349/IBM-Endpoint-Manager-For-Mobile-Devices-Code-Execution.html
Exploit mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Dec/3
Scores
EPSS
0.0649
EPSS Percentile
93.0%
Details
CWE
CWE-310
Status
published
Products (1)
ibm/tivoli_endpoint_manager_mobile_device_management
< 9.0
Published
Dec 06, 2014
Tracked Since
Feb 18, 2026