The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Tivoli_provisioning_manager_os_deployment | Ibm | 5.1.0.116 (including) | 5.1.0.116 (including) |