First published: Sat Jun 14 2014(Updated: )
IBM PureApplication System 1.0 before 1.0.0.4 cfix8 and 1.1 before 1.1.0.4 IF1 allows remote authenticated users to bypass intended access restrictions by establishing an SSH session from a deployed virtual machine.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM PureApplication System | =1.0.0.0 | |
IBM PureApplication System | =1.0.0.1 | |
IBM PureApplication System | =1.0.0.2 | |
IBM PureApplication System | =1.0.0.3 | |
IBM PureApplication System | =1.0.0.4 | |
IBM PureApplication System | =1.1.0.0 | |
IBM PureApplication System | =1.1.0.1 | |
IBM PureApplication System | =1.1.0.2 | |
IBM PureApplication System | =1.1.0.3 | |
IBM PureApplication System | =1.1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0960 is considered to be of medium severity due to its potential for unauthorized access.
To fix CVE-2014-0960, upgrade to IBM PureApplication System version 1.0.0.4 cfix8 or 1.1.0.4 IF1 or later.
CVE-2014-0960 affects IBM PureApplication System versions 1.0.0.0 through 1.0.0.4 and 1.1.0.0 through 1.1.0.4.
CVE-2014-0960 allows remote authenticated users to bypass access restrictions through an SSH session.
There is no official workaround for CVE-2014-0960; applying the official updates is recommended for mitigation.