Lucene search

K
cveIbmCVE-2013-5455
HistoryDec 07, 2013 - 5:33 a.m.

CVE-2013-5455

2013-12-0705:33:32
CWE-264
ibm
web.nvd.nist.gov
22
ibm
smartcloud
provisioning
security
vulnerability
remote
authenticated
virtual system
deployment
cli command

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

49.3%

IBM SmartCloud Provisioning 2.1 before FP3 IF0001 allows remote authenticated users to modify virtual-system deployment via deployer.virtualsystems CLI commands, as demonstrated by a deletion using a deployer.virtualsystems[#].delete command.

Affected configurations

Nvd
Node
ibmsmartcloud_provisioningMatch2.1.0
VendorProductVersionCPE
ibmsmartcloud_provisioning2.1.0cpe:2.3:a:ibm:smartcloud_provisioning:2.1.0:*:*:*:*:*:*:*

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:N/I:P/A:P

AI Score

6.2

Confidence

Low

EPSS

0.001

Percentile

49.3%

Related for CVE-2013-5455