CVE-2015-1937 - Improper Access Control

Severity

75%

Complexity

99%

Confidentiality

106%

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.

CVSS 2.0 Base Score 7.5. CVSS Attack Vector: network. CVSS Attack Complexity: low. CVSS Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).

Overview

Type

IBM PowerVC

First reported 10 years ago

2015-05-30 19:59:00

Last updated 8 years ago

2016-11-30 03:00:00

Affected Software

IBM PowerVC Express Edition 1.2.0.0

1.2.0.0

IBM PowerVC Standard Edition 1.2.0.0

1.2.0.0

IBM PowerVC Express Edition 1.2.0.1

1.2.0.1

IBM PowerVC Standard Edition 1.2.0.1

1.2.0.1

IBM PowerVC Express Edition 1.2.0.2

1.2.0.2

IBM PowerVC Standard Edition 1.2.0.2

1.2.0.2

IBM PowerVC Express Edition 1.2.0.3

1.2.0.3

IBM PowerVC Standard Edition 1.2.0.3

1.2.0.3

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.