Vulnerability record · CVE-2007-1868 · published 4 April 2007
CVE-2007-1868: IBM Tivoli Provisioning Manager OS Deployment management service RCE via multipart POST
Ibm · Tivoli Provisioning Manager Os Deployment
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 mishandles multipart/form-data in HTTP POST requests. Crafted POST requests to port 8080/tcp or 443/tcp can trigger arbitrary code execution or crash the daemon. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.
Description
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS v2 base score of 10 and high EPSS probability, though no confirmed in-the-wild exploitation is recorded.
What it is
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 mishandles multipart/form-data in HTTP POST requests. Crafted POST requests to port 8080/tcp or 443/tcp can trigger arbitrary code execution or crash the daemon. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.
Impact
An unauthenticated remote attacker can execute arbitrary code in the context of the management service or crash it, giving full compromise of confidentiality, integrity and availability on the affected host.
Attack surface
Reached over the network via HTTP POST to the management service on 8080/tcp or 443/tcp; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high (0.59338, 99.075th percentile), suggesting meaningful likelihood of attempted exploitation.
What to do
- Apply IBM Tivoli Provisioning Manager for OS Deployment 5.1 Fix Pack 2 or later (vendor patch referenced in the advisory).
- Restrict network access to the management service on 8080/tcp and 443/tcp to trusted administrative networks only.
- Place the management interface behind a reverse proxy or firewall that validates and normalizes multipart/form-data requests.
- Monitor and log POST requests to the management service for malformed multipart bodies and alert on daemon crashes.
- If the product is end-of-life or unpatchable, isolate the host and plan migration or decommissioning.
Detection
- Inspect HTTP server and application logs for POST requests to the management service with malformed or oversized multipart/form-data bodies.
- Alert on unexpected restarts or crashes of the Tivoli Provisioning Manager management daemon.
- Monitor network traffic to 8080/tcp and 443/tcp for anomalous POST patterns from untrusted sources.
- Correlate host process creation events on the Tivoli server with inbound management-service requests to spot post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1868 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1868), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.