Vulnerabilities > IBM > Integrated Management Module Firmware > 1.43

DATE CVE VULNERABILITY TITLE RISK
2018-04-25 CVE-2014-0881 Improper Access Control vulnerability in IBM Integrated Management Module Firmware 1.36/1.43
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an incorrect configuration.
network
ibm CWE-284
5.8
2017-06-20 CVE-2017-3744 Information Exposure Through Log Files vulnerability in multiple products
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running.
network
low complexity
lenovo ibm CWE-532
4.0