First published: Thu Oct 28 2010(Updated: )
** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only."
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Tivoli Provisioning Manager Os Deployment | =7.1.1.3 | |
=7.1.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2010-4121 is considered a critical vulnerability due to the lack of authentication allowing unauthorized database access.
To address CVE-2010-4121, implement proper authentication mechanisms for the TCP-to-ODBC gateway.
CVE-2010-4121 affects IBM Tivoli Provisioning Manager for OS Deployment version 7.1.1.3.
Yes, CVE-2010-4121 allows remote attackers to modify, create, or read database records without authentication.
Yes, the vendor disputes the issue related to CVE-2010-4121.