Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0882


Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.


Published

2018-04-25T20:29:00.447

Last Modified

2024-11-21T02:02:58.330

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-200

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm integrated_management_module_firmware 3.50 Yes
Operating System ibm integrated_management_module_firmware 3.55 Yes
Operating System ibm integrated_management_module_firmware 3.56 Yes
Operating System ibm integrated_management_module_firmware 3.65 Yes
Operating System ibm integrated_management_module_firmware 3.67 Yes
Hardware ibm flex_system_manager_7955 - No
Hardware ibm flex_system_manager_8731 - No
Hardware ibm flex_system_x220 - No
Hardware ibm flex_system_x240 - No
Hardware ibm flex_system_x440 - No
Hardware ibm nextscale_nx360_m4 - No
Hardware ibm system_x_idataplex_dx360_m4 - No
Hardware ibm system_x3100_m4 - No
Hardware ibm system_x3250_m4 - No
Hardware ibm system_x3500_m4 - No
Hardware ibm system_x3530_m4 - No
Hardware ibm system_x3550_m4 - No
Hardware ibm system_x3630_m4 - No
Hardware ibm system_x3650_m4 - No
Hardware ibm system_x3750_m4 - No

References