Vulnerabilities > IBM > System X3630 M3

DATE CVE VULNERABILITY TITLE RISK
2014-01-21 CVE-2013-4030 Cryptographic Issues vulnerability in IBM products
Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic.
network
ibm CWE-310
4.3
2013-08-09 CVE-2013-4038 Cryptographic Issues vulnerability in IBM products
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file.
network
low complexity
ibm CWE-310
4.0
2013-08-09 CVE-2013-4037 Authentication Bypass vulnerability in Intelligent Platform Management Interface
The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.
network
ibm
4.3
2013-08-09 CVE-2013-4031 Credentials Management vulnerability in IBM products
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.
network
low complexity
ibm CWE-255
critical
10.0