CVE-2010-4121
Last modified
CVE-2010-4121 is a vulnerability of currently unknown severity. The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.. EPSS estimates a 3.22% chance of exploitation in the next 30 days.
Description
The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Tivoli Provisioning Manager Os Deployment | 7.1.1.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-4121?
How severe is CVE-2010-4121?
How do I fix CVE-2010-4121?
Are you affected by CVE-2010-4121?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
