PT-2014-5084 · Ibm · Ibm Powervc

Published

2014-08-29

·

Updated

2017-08-29

·

CVE-2014-3093

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions IBM PowerVC versions 1.2.0 through 1.2.0 before FP3 IBM PowerVC versions 1.2.1 through 1.2.1 before FP2
Description The issue allows local users to obtain sensitive information. This is because cleartext passwords are used in various components, including api-paste.ini, debug logs, the installation process, environment checks, powervc-ldap-config, powervc-restore, and powervc-diag. A local user can exploit this by entering a ps command or reading a file.
Recommendations For IBM PowerVC version 1.2.0 before FP3, update to FP3 or later. For IBM PowerVC version 1.2.1 before FP2, update to FP2 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-3093

Affected Products

Ibm Powervc