A serious vulnerability identified in IBM’s Tivoli Endpoint Manager software — which allows for central management of mobile devices in a network — could give hackers a back door to push malicious code onto linked devices.
The Tivoli MDM software is on IT Schedule 70 and used by several civilian and defense agencies, including the Federal Communications Commission, National Institutes of Health, Army and Navy.
The vulnerability — coded CV-2014-6140 — allows an attacker to interject seemingly valid cookies that then execute arbitrary code when pushed to the devices managed by the system. The code is run with full administrator privileges, which could significantly compromise a device.
“It is highly likely that a successful attack on the application server can also be leveraged into a full compromise of all devices managed through the product,” German cybersecurity firm RedTeam Pentesting GmbH wrote in an advisory on Dec. 2. “This constitutes a high risk.”
The weakness — discovered by RedTeam during a penetration test earlier this year — was given a vulnerability score of 9.3 on a scale of 10.
IBM released a patch through version 9.0.60100 to remediate the issue, the company said in a security bulletin posted Dec. 4.
RedTeam offered a potential workaround, however it is untested. Like IBM, the firm suggests upgrading to a new version of the software.




