CVE-2010-4121 - CVE House
Back to Database
Status published High CVE-2010-4121

The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS...

Vulnerability Description

The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2010-4121

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

tivoli provisioning manager os deployment
Vulnerable Versions:
7.1.1.3

Timeline

Official Publish: October 28th, 2010
Last Modified: September 17th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.