Vulnerabilities > IBM > Powervc > 1.2.0.3
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2015-05-30 | CVE-2015-1937 | Improper Access Control vulnerability in IBM Powervc IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017. | 7.5 |
2015-03-24 | CVE-2015-0137 | Improper Input Validation vulnerability in IBM Powervc IBM PowerVC Standard 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 validates Hardware Management Console (HMC) certificates only during the pre-login stage, which allows man-in-the-middle attackers to spoof devices via a crafted certificate. | 4.3 |
2015-03-24 | CVE-2015-0136 | Information Exposure vulnerability in IBM Powervc powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process. | 2.1 |