First published: Wed Apr 25 2018(Updated: )
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an incorrect configuration. IBM X-Force ID: 91146.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Integrated Management Module II Firmware | >=1.00<=3.56 | |
IBM Flex System X222 M4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0881 is considered a high severity vulnerability due to the potential for remote attackers to exploit sensitive key information.
To fix CVE-2014-0881, ensure that your Integrated Management Module II (IMM2) is properly configured and updated to the latest firmware version.
CVE-2014-0881 affects IBM Flex System x222 servers running IMM2 firmware versions from 1.00 to 3.56.
CVE-2014-0881 can lead to sensitive information disclosure or denial of service if exploited by an attacker.
While the best solution is to apply the firmware update, ensuring proper configuration can act as a temporary workaround for CVE-2014-0881.