PT-2015-4495 · Ibm · Ibm Powervc
Publicado
2015-03-24
·
Atualizado
2015-03-24
·
CVE-2015-0136
CVSS v2.0
2.1
Baixa
| Vetor | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
IBM PowerVC versions 1.2.0.x through 1.2.0.3
IBM PowerVC versions 1.2.1.x through 1.2.1.x before 1.2.2
Description
The issue allows local users to obtain sensitive information by listing the process, as an access token is placed on the command line during IVM and PowerKVM management.
Recommendations
For IBM PowerVC versions 1.2.0.x through 1.2.0.3, update to version 1.2.0.4 or later.
For IBM PowerVC versions 1.2.1.x through 1.2.1.x before 1.2.2, update to version 1.2.2 or later.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ibm Powervc