Vulnerabilities > IBM > Tivoli Management Framework

DATE CVE VULNERABILITY TITLE RISK
2011-06-02 CVE-2011-2330 Permissions, Privileges, and Access Controls vulnerability in IBM Tivoli Management Framework
Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 has an unspecified "built-in account" that is "trivially" accessed, which makes it easier for remote attackers to send requests to restricted pages via a session on TCP port 9495, a different vulnerability than CVE-2011-1220.
network
low complexity
ibm CWE-264
critical
9.0
2011-06-02 CVE-2011-1220 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in IBM Tivoli Management Framework
Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3.1 allows remote authenticated users to execute arbitrary code via a long opts field.
network
low complexity
ibm CWE-119
critical
9.0
2005-07-11 CVE-2005-2170 Remote Denial Of Service vulnerability in IBM Tivoli Management Framework 4.1.1
The LCF component (lcfd) in IBM Tivoli Management Framework Endpoint allows remote attackers to cause a denial of service (process exit and connection loss) by connecting to LCF and ending the connection without sending any data.
network
low complexity
ibm
5.0
2002-10-04 CVE-2002-1012 Buffer Overrun vulnerability in IBM Tivoli Management Framework ManagedNode
Buffer overflow in web server for Tivoli Management Framework (TMF) ManagedNode 3.6.x through 3.7.1 allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
network
low complexity
ibm
7.5
2002-10-04 CVE-2002-1011 Buffer Overflow vulnerability in IBM Tivoli Management Framework Endpoint
Buffer overflow in web server for Tivoli Management Framework (TMF) Endpoint 3.6.x through 3.7.1, before Fixpack 2, allows remote attackers to cause a denial of service or execute arbitrary code via a long HTTP GET request.
network
low complexity
ibm
7.5
2000-12-31 CVE-2000-1239 Information Disclosure vulnerability in IBM Tivoli Management Framework 3.7.1
The HTTP interface of Tivoli Lightweight Client Framework (LCF) in IBM Tivoli Management Framework 3.7.1 sets http_disable to zero at install time, which allows remote authenticated users to bypass file permissions on Tivoli Endpoint Configuration data files via an unspecified manipulation of log files.
network
low complexity
ibm
critical
9.0