First published: Sat Dec 07 2013(Updated: )
IBM SmartCloud Provisioning 2.1 before FP3 IF0001 allows remote authenticated users to modify virtual-system deployment via deployer.virtualsystems CLI commands, as demonstrated by a deletion using a deployer.virtualsystems[#].delete command.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM SmartCloud Provisioning | =2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5455 is considered a high severity vulnerability due to the potential for remote authenticated users to modify virtual system configurations.
To fix CVE-2013-5455, apply IBM SmartCloud Provisioning version 2.1 FP3 IF0001 or later.
CVE-2013-5455 affects IBM SmartCloud Provisioning version 2.1.0 prior to FP3 IF0001.
Yes, CVE-2013-5455 allows authenticated users to execute deployer.virtualsystems.delete commands, potentially leading to unauthorized data deletion.
No, simply requiring user authentication does not mitigate CVE-2013-5455 since authenticated users can still exploit the vulnerability.