PT-2021-5272 · Ibm · Ibm System X 3650 M3+1

Published

2021-09-14

·

Updated

2021-11-17

·

CVE-2021-3723

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IBM System x 3550 M3 (affected versions not specified) IBM System x 3650 M3 (affected versions not specified)
Description A command injection issue was found in the Integrated Management Module (IMM) that could allow the execution of operating system commands over an authenticated SSH or Telnet session. This is due to the lack of neutralization of special elements used in the operating system command. Exploitation of this issue may allow a remote attacker to execute arbitrary operating system commands.
Recommendations For IBM System x 3550 M3, at the moment, there is no information about a newer version that contains a fix for this issue. For IBM System x 3650 M3, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-06098
CVE-2021-3723

Affected Products

Ibm System X 3550 M3
Ibm System X 3650 M3