Lucene search

K
cveMitreCVE-2008-0401
HistoryJan 23, 2008 - 12:00 p.m.

CVE-2008-0401

2008-01-2312:00:00
CWE-119
mitre
web.nvd.nist.gov
26
cve-2008-0401
buffer overflow
http server
ibm tivoli provisioning manager
security vulnerability

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.819

Percentile

98.4%

Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via an HTTP request with a long method string to port 443/tcp.

Affected configurations

Nvd
Node
ibmtivoli_provisioning_manager_os_deploymentRange≀5.1.0.2
VendorProductVersionCPE
ibmtivoli_provisioning_manager_os_deployment*cpe:2.3:a:ibm:tivoli_provisioning_manager_os_deployment:*:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.8

Confidence

Low

EPSS

0.819

Percentile

98.4%