mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 01:02:25 +00:00
138 lines
4.7 KiB
JSON
138 lines
4.7 KiB
JSON
{
|
|
"id": "CVE-2015-0136",
|
|
"sourceIdentifier": "psirt@us.ibm.com",
|
|
"published": "2015-03-24T00:59:03.233",
|
|
"lastModified": "2015-03-24T14:28:53.453",
|
|
"vulnStatus": "Analyzed",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "powervc-iso-import en IBM PowerVC 1.2.0.x anerior a 1.2.0.4 y 1.2.1.x anterior a 1.2.2 coloca un token de acceso en la l\u00ednea de comandos durante la gesti\u00f3n IVM y PowerKVM, lo que permite a usuarios locales obtener informaci\u00f3n sensible mediante el listado del proceso."
|
|
}
|
|
],
|
|
"metrics": {
|
|
"cvssMetricV2": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"cvssData": {
|
|
"version": "2.0",
|
|
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
|
|
"accessVector": "LOCAL",
|
|
"accessComplexity": "LOW",
|
|
"authentication": "NONE",
|
|
"confidentialityImpact": "PARTIAL",
|
|
"integrityImpact": "NONE",
|
|
"availabilityImpact": "NONE",
|
|
"baseScore": 2.1
|
|
},
|
|
"baseSeverity": "LOW",
|
|
"exploitabilityScore": 3.9,
|
|
"impactScore": 2.9,
|
|
"acInsufInfo": false,
|
|
"obtainAllPrivilege": false,
|
|
"obtainUserPrivilege": false,
|
|
"obtainOtherPrivilege": false,
|
|
"userInteractionRequired": false
|
|
}
|
|
]
|
|
},
|
|
"weaknesses": [
|
|
{
|
|
"source": "nvd@nist.gov",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-200"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"configurations": [
|
|
{
|
|
"nodes": [
|
|
{
|
|
"operator": "OR",
|
|
"negate": false,
|
|
"cpeMatch": [
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "F235BE09-8C8A-47DB-8FEB-1DB75B033143"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:standard:*:*:*",
|
|
"matchCriteriaId": "588EBB92-23C4-425B-9093-F776323B05F3"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "603F587A-2B4B-4FCD-B0AD-EE07553CB485"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:standard:*:*:*",
|
|
"matchCriteriaId": "AB78B5FF-E4F3-483D-A3BF-F2E2ED997DEF"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "68534B6C-B5EC-4F62-AF41-DDCE3C10ACBD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:standard:*:*:*",
|
|
"matchCriteriaId": "C1626D53-458F-4EE2-9CA5-EFF2B819B5CB"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.3:*:*:*:express:*:*:*",
|
|
"matchCriteriaId": "C9C4784D-B903-461C-9B50-0BD8BBE1FF41"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.3:*:*:*:standard:*:*:*",
|
|
"matchCriteriaId": "12201638-3C87-480B-A5A1-371A1FB37056"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.0:-:-:-:express:*:*:*",
|
|
"matchCriteriaId": "BAAFA0F7-0187-437B-846B-A267BE7751A0"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.0:-:-:-:standard:*:*:*",
|
|
"matchCriteriaId": "6F9A7FC3-8028-4B81-A0A3-E52C21986FDD"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.1:-:-:-:express:*:*:*",
|
|
"matchCriteriaId": "3D451202-57AC-4D09-BE16-043AF4206C3E"
|
|
},
|
|
{
|
|
"vulnerable": true,
|
|
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.1:-:-:-:standard:*:*:*",
|
|
"matchCriteriaId": "E23B23F7-C755-435E-AA2B-05F2B3966816"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "http://www-01.ibm.com/support/docview.wss?uid=nas8N1020608",
|
|
"source": "psirt@us.ibm.com",
|
|
"tags": [
|
|
"Vendor Advisory"
|
|
]
|
|
}
|
|
]
|
|
} |