Menu
IBM fixes serious flaw in Endpoint Manager for mobile device management

IBM fixes serious flaw in Endpoint Manager for mobile device management

The flaw can be exploited to execute arbitrary code on the management server

A vulnerability in the IBM Endpoint Manager for mobile devices could allow attackers to execute malicious code on the servers used by companies to manage devices.

The IBM Endpoint Manager Mobile Device Management (MDM) product provides companies with management, security and reporting functionality for mobile devices.

Researchers from a German security firm called RedTeam Pentesting discovered that authentication cookies for several IBM Endpoint Manager components are protected with a hardcoded static secret token that can be easily obtained. The affected components are iOS extender, Self-service portal, Trusted Services provider and Admin Portal.

"Once the secret is known, arbitrary cookie values can be crafted and sent to the respective application for further processing," the RedTeam researchers said in a security advisory. This can then be used to execute arbitrary code on the IBM Endpoint Manager server, they said.

"The vulnerability allows unauthenticated remote attackers to execute arbitrary code with administrative privileges on the affected systems," the researchers said. "It is highly likely that a successful attack on the application server can also be leveraged into a full compromise of all devices managed through the product."

IBM released version 9.0.60100 of the product in order to address the vulnerability and also published a security bulletin. There are no workarounds or mitigations, so users should upgrade to the new version as soon as possible.


Follow Us

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags securitymobile securityIBMpatchesAccess control and authenticationExploits / vulnerabilitiesRedTeam Pentesting

Featured

Slideshows

Meet the leading female front runners of the Kiwi channel

Meet the leading female front runners of the Kiwi channel

Reseller News honoured the leading female front runners of the New Zealand channel at the 2018 Women in ICT Awards (WIICTA) in Auckland. The awards honoured standout individuals across seven categories, spanning Entrepreneur; Innovation; Rising Star; Shining Star; Community; Technical and Achievement.

Meet the leading female front runners of the Kiwi channel
Meet the top performing customer-centric Microsoft channel partners

Meet the top performing customer-centric Microsoft channel partners

Microsoft honoured leading partners across the channel following a year of customer innovation and market growth in New Zealand. The 2018 Microsoft Partner Awards recognised excellence within the context of the end-user, spanning a host of emerging and established providers.

Meet the top performing customer-centric Microsoft channel partners
Reseller News launches new-look Awards at 2018 Judges’ Lunch

Reseller News launches new-look Awards at 2018 Judges’ Lunch

Introducing the Reseller News Innovation Awards, launched to the channel at the 2018 Judges’ Lunch in Auckland. With more than 70 judges now part of the voting panel, the new-look awards will reflect the changing dynamics of the channel, recognising excellence across customer value and innovation - spanning start-ups, partners, distributors and vendors.

Reseller News launches new-look Awards at 2018 Judges’ Lunch
Show Comments