IBM Tivoli Management Framework Endpoint addr URL Default Credentials

This script is Copyright (C) 2011-2015 Tenable Network Security, Inc.

Synopsis :

It is possible to authenticate to the remote server using the default

Description :

The remote Tivoli Endpoint installation is secured by default
credentials. Nessus is able to make authenticated requests to '/addr'
by using the username 'tivoli' and password 'boss', which are
hard-coded in the server executable.

A remote, unauthenticated attacker could change the endpoint's
configuration or disable the web interface by using these default

See also :

Solution :

Disable the ability to change endpoint configuration from the browser
using the 'http_disable' configuration setting. Refer to the IBM
documentation for more information.

Risk factor :

High / CVSS Base Score : 7.5
Public Exploit Available : true

Family: Web Servers

Nessus Plugin ID: 54987 ()

Bugtraq ID: