First published: Tue Mar 24 2015(Updated: )
powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM PowerVC | =1.2.0.0 | |
IBM PowerVC | =1.2.0.0 | |
IBM PowerVC | =1.2.0.1 | |
IBM PowerVC | =1.2.0.1 | |
IBM PowerVC | =1.2.0.2 | |
IBM PowerVC | =1.2.0.2 | |
IBM PowerVC | =1.2.0.3 | |
IBM PowerVC | =1.2.0.3 | |
IBM PowerVC | =1.2.1.0 | |
IBM PowerVC | =1.2.1.0 | |
IBM PowerVC | =1.2.1.1 | |
IBM PowerVC | =1.2.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.