HIGH · 8.5

CVE-2008-5686

IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows...

Vulnerability Description

IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows remote authenticated users to execute SOAP commands that access arbitrary TPM functionality, as demonstrated by running provisioning workflows.

CVSS Score

8.5

HIGH

AV:N/AC:M/Au:S/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
IbmTivoli Provisioning Manager5.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2008-5686?

CVE-2008-5686 is a vulnerability with a CVSS score of 8.5 (HIGH). IBM Tivoli Provisioning Manager (TPM) before 5.1.1.1 IF0006, when its LDAP service is shared with other applications, does not require that an LDAP user be listed in the TPM user records, which allows...

How severe is CVE-2008-5686?

CVE-2008-5686 has been rated HIGH with a CVSS base score of 8.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-5686?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Tivoli Provisioning Manager.