Vulnerabilities > IBM > Powervc > 1.2.0.0

DATE CVE VULNERABILITY TITLE RISK
2015-05-30 CVE-2015-1937 Improper Access Control vulnerability in IBM Powervc
IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.
network
low complexity
ibm CWE-284
7.5
2015-03-24 CVE-2015-0137 Improper Input Validation vulnerability in IBM Powervc
IBM PowerVC Standard 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 validates Hardware Management Console (HMC) certificates only during the pre-login stage, which allows man-in-the-middle attackers to spoof devices via a crafted certificate.
network
ibm CWE-20
4.3
2015-03-24 CVE-2015-0136 Information Exposure vulnerability in IBM Powervc
powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process.
local
low complexity
ibm CWE-200
2.1
2014-08-29 CVE-2014-3093 Cryptographic Issues vulnerability in IBM Powervc
IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local users to obtain sensitive information by entering a ps command or reading a file.
local
low complexity
ibm CWE-310
2.1
2014-08-20 CVE-2014-4750 Information Exposure vulnerability in IBM Powervc 1.2.0.0/1.2.0.1/1.2.0.2
IBM PowerVC Express Edition 1.2.0 before FixPack3 establishes an FTP session for transferring files to a managed IVM, which allows remote attackers to discover credentials by sniffing the network.
2.9
2014-08-20 CVE-2014-4749 Permissions, Privileges, and Access Controls vulnerability in IBM Powervc 1.2.0.0/1.2.0.1/1.2.0.2
IBM PowerVC 1.2.0 before FixPack3 does not properly use the known_hosts file, which allows man-in-the-middle attackers to spoof SSH servers via an arbitrary server key.
network
ibm CWE-264
4.3