PT-2021-5272 · Ibm · Ibm System X 3650 M3+1
Published
2021-09-14
·
Updated
2021-11-17
·
CVE-2021-3723
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM System x 3550 M3 (affected versions not specified)
IBM System x 3650 M3 (affected versions not specified)
Description
A command injection issue was found in the Integrated Management Module (IMM) that could allow the execution of operating system commands over an authenticated SSH or Telnet session. This is due to the lack of neutralization of special elements used in the operating system command. Exploitation of this issue may allow a remote attacker to execute arbitrary operating system commands.
Recommendations
For IBM System x 3550 M3, at the moment, there is no information about a newer version that contains a fix for this issue.
For IBM System x 3650 M3, at the moment, there is no information about a newer version that contains a fix for this issue.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm System X 3550 M3
Ibm System X 3650 M3