CVE Vulnerabilities

CVE-2014-3093

Published: Aug 29, 2014 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

IBM PowerVC 1.2.0 before FP3 and 1.2.1 before FP2 uses cleartext passwords in (1) api-paste.ini, (2) debug logs, (3) the installation process, (4) environment checks, (5) powervc-ldap-config, (6) powervc-restore, and (7) powervc-diag, which allows local users to obtain sensitive information by entering a ps command or reading a file.

Affected Software

Name Vendor Start Version End Version
Powervc Ibm 1.2.0.0 (including) 1.2.0.0 (including)
Powervc Ibm 1.2.0.1 (including) 1.2.0.1 (including)
Powervc Ibm 1.2.0.2 (including) 1.2.0.2 (including)
Powervc Ibm 1.2.1.0 (including) 1.2.1.0 (including)
Powervc Ibm 1.2.1.1 (including) 1.2.1.1 (including)

References