Lucene search

K
ibmIBMAD8416B862DEF19C3E48462278D7993BC23525123A414C121FFA08440D8919C1
HistoryJun 17, 2018 - 10:30 p.m.

Security Bulletin: Vulnerability in qemu-kvm affects IBM SmartCloud Provisioning for IBM Software Virtual Appliance

2018-06-1722:30:14
www.ibm.com
12

0.003 Low

EPSS

Percentile

71.4%

Summary

Security Bulletin: Vulnerability in qemu-kvm affects IBM SmartCloud Provisioning for IBM Software Virtual Appliance (CVE-2015-5165).

Vulnerability Details

CVEID: CVE-2015-5165**
DESCRIPTION:** Xen could allow a local attacker to obtain sensitive information, caused by the improper validation of input in the C+ mode offload emulation by the QEMU model of the RTL8139 network card. An attacker could exploit this vulnerability to obtain host-level data.
CVSS Base Score: 6.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/105254 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

Affected Products and Versions

IBM SmartCloud Provisioning 2.1 for IBM Software Virtual Appliance

Remediation/Fixes

If you are running IBM SmartCloud Provisioning 2.1 for IBM Software Virtual Appliance, contact IBM support.

Workarounds and Mitigations

None