First published: Wed Jul 01 2015(Updated: )
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM PowerVC | =1.2.2.1 | |
IBM PowerVC | =1.2.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1950 is classified as a medium severity vulnerability due to unauthorized access to sensitive credentials.
To fix CVE-2015-1950, ensure that proper authentication is enforced for access to the PowerVC Python interpreter.
CVE-2015-1950 affects IBM PowerVC Standard Edition versions 1.2.2.1 and 1.2.2.2.
CVE-2015-1950 allows KVM guest OS users to potentially discover PowerVC credentials, leading to unauthorized actions.
Users of IBM PowerVC Standard Edition versions 1.2.2.1 and 1.2.2.2 are affected by CVE-2015-1950.