HIGH · 9.3

CVE-2014-6140

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrar...

Vulnerability Description

IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrary code via crafted marshalled Ruby objects in cookies to (1) Enrollment and Apple iOS Management Extender, (2) Self-service portal, (3) Trusted Services provider, or (4) Admin Portal.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
IbmTivoli Endpoint Manager Mobile Device Management<= 9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-6140?

CVE-2014-6140 is a vulnerability with a CVSS score of 9.3 (HIGH). IBM Tivoli Endpoint Manager Mobile Device Management (MDM) before 9.0.60100 uses the same secret HMAC token across different customers' installations, which allows remote attackers to execute arbitrar...

How severe is CVE-2014-6140?

CVE-2014-6140 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-6140?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Tivoli Endpoint Manager Mobile Device Management.