CVE-2010-2656: Medium severity ibm advanced management module firmware vulnerability
The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2656?
CVE-2010-2656 is considered a high severity vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2010-2656?
To fix CVE-2010-2656, it is recommended to update the IBM Advanced Management Module firmware to version 4.7 or later.
What type of information can be exposed in CVE-2010-2656?
CVE-2010-2656 can expose sensitive log files and core files allowing attackers to gain insight into the system.
Who is affected by CVE-2010-2656?
Users of the IBM BladeCenter with Advanced Management Module firmware versions before 4.7 and 5.0 are affected by CVE-2010-2656.
Can CVE-2010-2656 be exploited remotely?
Yes, CVE-2010-2656 can be exploited remotely by attackers to download sensitive files.