vendor:
IBM Tivoli Endpoint
by:
Jeremy Brown
7.5
CVSS
HIGH
Stack-based buffer overflow
Not mentioned
CWE
Product Name: IBM Tivoli Endpoint
Affected Version From: Tivoli Endpoint 4.1.1-LCF-0048
Affected Version To: Not mentioned
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Windows XP SP3
2011
IBM Tivoli Endpoint 4.1.1 Remote SYSTEM Exploit
This exploit makes use of two vulnerabilities: 1) Base64 authentication credentials hard-coded in lcfd.exe 2) Stack-based buffer overflow when parsing HTTP variable values
Mitigation:
Not mentioned