CVE-2015-0136
Summary
| CVE | CVE-2015-0136 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-24 00:59:00 UTC |
| Updated | 2015-03-24 14:28:00 UTC |
| Description | powervc-iso-import in IBM PowerVC 1.2.0.x before 1.2.0.4 and 1.2.1.x before 1.2.2 places an access token on the command line during IVM and PowerKVM management, which allows local users to obtain sensitive information by listing the process. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ibm | Powervc | 1.2.0.0 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.0 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.1 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.1 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.2 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.2 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.3 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.3 | All | All | All |
| Application | Ibm | Powervc | 1.2.1.0 | - | - | - |
| Application | Ibm | Powervc | 1.2.1.0 | - | - | - |
| Application | Ibm | Powervc | 1.2.1.1 | - | - | - |
| Application | Ibm | Powervc | 1.2.1.1 | - | - | - |
| Application | Ibm | Powervc | 1.2.0.0 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.0 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.1 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.1 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.2 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.2 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.3 | All | All | All |
| Application | Ibm | Powervc | 1.2.0.3 | All | All | All |
| Application | Ibm | Powervc | 1.2.1.0 | - | - | - |
| Application | Ibm | Powervc | 1.2.1.0 | - | - | - |
| Application | Ibm | Powervc | 1.2.1.1 | - | - | - |
| Application | Ibm | Powervc | 1.2.1.1 | - | - | - |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| IBM Security Bulletin: IBM PowerVC Could Allow a Local Attacker to Read a Valid Access Token (CVE-2015-0136) - United States | CONFIRM | www-01.ibm.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.