2.1

CVE-2014-3093

IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local users to obtain sensitive information by entering a ps command or reading a file.

Data is provided by the National Vulnerability Database (NVD)
IbmPowervc Version1.2.0.0 SwEditionexpress
IbmPowervc Version1.2.0.0 SwEditionstandard
IbmPowervc Version1.2.0.1 SwEditionexpress
IbmPowervc Version1.2.0.1 SwEditionstandard
IbmPowervc Version1.2.0.2 SwEditionexpress
IbmPowervc Version1.2.0.2 SwEditionstandard
IbmPowervc Version1.2.1.0 SwEditionexpress
IbmPowervc Version1.2.1.0 SwEditionstandard
IbmPowervc Version1.2.1.1 SwEditionexpress
IbmPowervc Version1.2.1.1 SwEditionstandard
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.139
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N