SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-1868

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service…

HIGH 10.0EPSS 59.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 59.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
59.34% probability · 99th percentile
CISA KEV
Not listed
Affected
ibm/tivoli provisioning manager os deployment
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.