CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
AV:N/AC:L/Au:S/C:P/I:N/A:N
AI Score
Confidence
Low
EPSS
Percentile
90.5%
private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | advanced_management_module | 1.36h | cpe:2.3:a:ibm:advanced_management_module:1.36h:*:*:*:*:*:*:* |
ibm | bladecenter | e | cpe:2.3:h:ibm:bladecenter:e:*:1881:*:*:*:*:* |
ibm | bladecenter | e | cpe:2.3:h:ibm:bladecenter:e:*:7967:*:*:*:*:* |
ibm | bladecenter | e | cpe:2.3:h:ibm:bladecenter:e:*:8677:*:*:*:*:* |
ibm | bladecenter | h | cpe:2.3:h:ibm:bladecenter:h:*:7989:*:*:*:*:* |
ibm | bladecenter | h | cpe:2.3:h:ibm:bladecenter:h:*:8852:*:*:*:*:* |
ibm | bladecenter | hc10 | cpe:2.3:h:ibm:bladecenter:hc10:*:7996:*:*:*:*:* |
ibm | bladecenter | hs12 | cpe:2.3:h:ibm:bladecenter:hs12:*:1916:*:*:*:*:* |
ibm | bladecenter | hs12 | cpe:2.3:h:ibm:bladecenter:hs12:*:8014:*:*:*:*:* |
ibm | bladecenter | hs12 | cpe:2.3:h:ibm:bladecenter:hs12:*:8028:*:*:*:*:* |