APP: IBM Tivoli Provisioning Manager for OS Deployment HTTP Server Buffer Overflow
This signature detects attempts to exploit a known vulnerability in the IBM Tivoli Provisioning Manager. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the affected application.
Extended Description
IBM Tivoli Provisioning Manager for OS Deployment is prone to a remote buffer-overflow vulnerability because it fails to properly perform size checks on user-supplied input. A remote attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges or to crash the server process, which could lead to denial-of-service conditions. Versions prior to IBM Tivoli Provisioning Manager for OS Deployment 5.1.0.3 are vulnerable. NOTE: This BID was previously titled 'IBM Tivoli Provisioning Manager for OS Deployment Denial of Service Vulnerability' but has been updated to reflect new information.
Affected Products
Ibm tivoli_provisioning_manager_for_os_deployment
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Ibm
10.0