First published: Wed Apr 04 2007(Updated: )
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Tivoli Provisioning Manager Os Deployment | =5.1.0.116 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1868 has a high severity rating due to its potential to allow remote code execution and denial of service.
To fix CVE-2007-1868, upgrade IBM Tivoli Provisioning Manager for OS Deployment to version 5.1 Fix Pack 2 or later.
CVE-2007-1868 can be exploited by sending crafted multipart/form-data in HTTP POST requests, allowing arbitrary code execution or causing daemon crashes.
CVE-2007-1868 affects IBM Tivoli Provisioning Manager for OS Deployment versions prior to 5.1 Fix Pack 2.
Yes, CVE-2007-1868 is directly related to how the management service handles multipart/form-data in HTTP POST requests.