← Vulnerability feed

Vulnerability record · CVE-2007-1868 · published 4 April 2007

CVE-2007-1868: IBM Tivoli Provisioning Manager OS Deployment management service RCE via multipart POST

Ibm · Tivoli Provisioning Manager Os Deployment

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 mishandles multipart/form-data in HTTP POST requests. Crafted POST requests to port 8080/tcp or 443/tcp can trigger arbitrary code execution or crash the daemon. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.

10.0 CVSS 2.0 High EPSS 59% · top 0.9%
10.0CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly handle multipart/form-data in HTTP POST requests, which allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via crafted POST requests to port 8080/tcp or 443/tcp.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityUnauthenticated remote code execution with a CVSS v2 base score of 10 and high EPSS probability, though no confirmed in-the-wild exploitation is recorded.

What it is

The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 mishandles multipart/form-data in HTTP POST requests. Crafted POST requests to port 8080/tcp or 443/tcp can trigger arbitrary code execution or crash the daemon. The flaw is remotely reachable without authentication and carries a maximum CVSS v2 base score of 10.

Impact

An unauthenticated remote attacker can execute arbitrary code in the context of the management service or crash it, giving full compromise of confidentiality, integrity and availability on the affected host.

Attack surface

Reached over the network via HTTP POST to the management service on 8080/tcp or 443/tcp; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is high (0.59338, 99.075th percentile), suggesting meaningful likelihood of attempted exploitation.

What to do

  • Apply IBM Tivoli Provisioning Manager for OS Deployment 5.1 Fix Pack 2 or later (vendor patch referenced in the advisory).
  • Restrict network access to the management service on 8080/tcp and 443/tcp to trusted administrative networks only.
  • Place the management interface behind a reverse proxy or firewall that validates and normalizes multipart/form-data requests.
  • Monitor and log POST requests to the management service for malformed multipart bodies and alert on daemon crashes.
  • If the product is end-of-life or unpatchable, isolate the host and plan migration or decommissioning.

Detection

  • Inspect HTTP server and application logs for POST requests to the management service with malformed or oversized multipart/form-data bodies.
  • Alert on unexpected restarts or crashes of the Tivoli Provisioning Manager management daemon.
  • Monitor network traffic to 8080/tcp and 443/tcp for anomalous POST patterns from untrusted sources.
  • Correlate host process creation events on the Tivoli server with inbound management-service requests to spot post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1868 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-1868), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.