CVE Vulnerabilities

CVE-2014-3093

Published: Aug 29, 2014 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local users to obtain sensitive information by entering a ps command or reading a file.

Affected Software

Name Vendor Start Version End Version
Powervc Ibm 1.2.0.0 (including) 1.2.0.0 (including)
Powervc Ibm 1.2.0.1 (including) 1.2.0.1 (including)
Powervc Ibm 1.2.0.2 (including) 1.2.0.2 (including)
Powervc Ibm 1.2.1.0 (including) 1.2.1.0 (including)
Powervc Ibm 1.2.1.1 (including) 1.2.1.1 (including)

References