Big Blue patches big blooper in Endpoint Manager for mobes

  • 4 December 2014
  • 0 replies
  • 124 views

Userlevel 7
By Darren Pauli, 4 Dec 2014
 
Big Blue has patched a serious hole in its Endpoint Manager for Mobile Devices that allows attackers to gain remote access and compromise connected mobes.
Endpoint Manager appears to have been written with Ruby, and the (flaw) means "attackers can create valid session cookies containing marshalled objects of their choosing," according to chaps at RedTeam Pentesting who have posted about the problem. "This can be leveraged to execute arbitrary code when the Ruby on Rails application unmarshals the cookie," their post says.
 
full article

0 replies

Be the first to reply!

Reply