René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

137 lines
4.6 KiB
JSON

{
"id": "CVE-2015-0136",
"sourceIdentifier": "psirt@us.ibm.com",
"published": "2015-03-24T00:59:03.233",
"lastModified": "2015-03-24T14:28:53.453",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process."
},
{
"lang": "es",
"value": "powervc-iso-import en IBM PowerVC 1.2.0.x anerior a 1.2.0.4 y 1.2.1.x anterior a 1.2.2 coloca un token de acceso en la l\u00ednea de comandos durante la gesti\u00f3n IVM y PowerKVM, lo que permite a usuarios locales obtener informaci\u00f3n sensible mediante el listado del proceso."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE",
"baseScore": 2.1
},
"baseSeverity": "LOW",
"exploitabilityScore": 3.9,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-200"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:express:*:*:*",
"matchCriteriaId": "F235BE09-8C8A-47DB-8FEB-1DB75B033143"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:standard:*:*:*",
"matchCriteriaId": "588EBB92-23C4-425B-9093-F776323B05F3"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:express:*:*:*",
"matchCriteriaId": "603F587A-2B4B-4FCD-B0AD-EE07553CB485"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:standard:*:*:*",
"matchCriteriaId": "AB78B5FF-E4F3-483D-A3BF-F2E2ED997DEF"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:express:*:*:*",
"matchCriteriaId": "68534B6C-B5EC-4F62-AF41-DDCE3C10ACBD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:standard:*:*:*",
"matchCriteriaId": "C1626D53-458F-4EE2-9CA5-EFF2B819B5CB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.3:*:*:*:express:*:*:*",
"matchCriteriaId": "C9C4784D-B903-461C-9B50-0BD8BBE1FF41"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.0.3:*:*:*:standard:*:*:*",
"matchCriteriaId": "12201638-3C87-480B-A5A1-371A1FB37056"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.0:-:-:-:express:*:*:*",
"matchCriteriaId": "BAAFA0F7-0187-437B-846B-A267BE7751A0"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.0:-:-:-:standard:*:*:*",
"matchCriteriaId": "6F9A7FC3-8028-4B81-A0A3-E52C21986FDD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.1:-:-:-:express:*:*:*",
"matchCriteriaId": "3D451202-57AC-4D09-BE16-043AF4206C3E"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:ibm:powervc:1.2.1.1:-:-:-:standard:*:*:*",
"matchCriteriaId": "E23B23F7-C755-435E-AA2B-05F2B3966816"
}
]
}
]
}
],
"references": [
{
"url": "http://www-01.ibm.com/support/docview.wss?uid=nas8N1020608",
"source": "psirt@us.ibm.com",
"tags": [
"Vendor Advisory"
]
}
]
}