PT-2013-5552 · Ibm · Ibm Smartcloud Provisioning

Published

2013-12-07

·

Updated

2017-08-29

·

CVE-2013-5455

CVSS v2.0

4.9

Medium

VectorAV:N/AC:M/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions IBM SmartCloud Provisioning version 2.1 before FP3 IF0001
Description The issue allows remote authenticated users to modify virtual-system deployment. This can be achieved via deployer.virtualsystems CLI commands. For example, a deletion can be performed using the deployer.virtualsystems[#].delete command.
Recommendations For IBM SmartCloud Provisioning version 2.1 before FP3 IF0001, apply FP3 IF0001 to resolve the issue. As a temporary workaround, consider restricting access to the deployer.virtualsystems CLI commands to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-5455

Affected Products

Ibm Smartcloud Provisioning