PowerKVM is affected by a vulnerability in libvirt. IBM has now addressed this vulnerability.
CVEID: CVE-2015-5160**
DESCRIPTION:** libvirt could allow a local attacker to obtain sensitive information, caused by the leak of private credentials to the process list. By accessing the process list, an attacker could exploit this vulnerability to obtain sensitive information and use this information to launch further attacks against the affected system.
CVSS Base Score: 4
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/119071 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
PowerKVM 2.1 and PowerKVM 3.1
Customers can update PowerKVM systems by using “yum update”.
Fix images are made available via Fix Central. For version 3.1, see https://ibm.biz/BdHggw. This issue is addressed starting with v3.1.0.2 update 7.
Customers using v2.1 can work around the problem by upgrading to the fixed version of v3.1.