Description
The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-17T03:42:49.634Z
Reserved: 2010-10-28T00:00:00.000Z
Link: CVE-2010-4121
No data.
Status : Modified
Published: 2010-10-28T21:00:14.950
Modified: 2026-04-29T01:13:23.040
Link: CVE-2010-4121
No data.
OpenCVE Enrichment
No data.
Weaknesses