Lucene search

K
nvd[email protected]NVD:CVE-2015-1937
HistoryMay 30, 2015 - 7:59 p.m.

CVE-2015-1937

2015-05-3019:59:02
CWE-284
web.nvd.nist.gov
1

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.008

Percentile

81.2%

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.

Affected configurations

Nvd
Node
ibmpowervcMatch1.2.0.0express
OR
ibmpowervcMatch1.2.0.0standard
OR
ibmpowervcMatch1.2.0.1express
OR
ibmpowervcMatch1.2.0.1standard
OR
ibmpowervcMatch1.2.0.2express
OR
ibmpowervcMatch1.2.0.2standard
OR
ibmpowervcMatch1.2.0.3express
OR
ibmpowervcMatch1.2.0.3standard
OR
ibmpowervcMatch1.2.0.4express
OR
ibmpowervcMatch1.2.0.4standard
OR
ibmpowervcMatch1.2.1.0express
OR
ibmpowervcMatch1.2.1.0standard
OR
ibmpowervcMatch1.2.1.1express
OR
ibmpowervcMatch1.2.1.2express
OR
ibmpowervcMatch1.2.1.2standard
OR
ibmpowervcMatch1.2.2.0express
OR
ibmpowervcMatch1.2.2.0standard
OR
ibmpowervcMatch1.2.2.1express
OR
ibmpowervcMatch1.2.2.1standard
OR
ibmpowervcMatch1.2.2.2express
OR
ibmpowervcMatch1.2.2.2standard
VendorProductVersionCPE
ibmpowervc1.2.0.0cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:express:*:*:*
ibmpowervc1.2.0.0cpe:2.3:a:ibm:powervc:1.2.0.0:*:*:*:standard:*:*:*
ibmpowervc1.2.0.1cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:express:*:*:*
ibmpowervc1.2.0.1cpe:2.3:a:ibm:powervc:1.2.0.1:*:*:*:standard:*:*:*
ibmpowervc1.2.0.2cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:express:*:*:*
ibmpowervc1.2.0.2cpe:2.3:a:ibm:powervc:1.2.0.2:*:*:*:standard:*:*:*
ibmpowervc1.2.0.3cpe:2.3:a:ibm:powervc:1.2.0.3:*:*:*:express:*:*:*
ibmpowervc1.2.0.3cpe:2.3:a:ibm:powervc:1.2.0.3:*:*:*:standard:*:*:*
ibmpowervc1.2.0.4cpe:2.3:a:ibm:powervc:1.2.0.4:*:*:*:express:*:*:*
ibmpowervc1.2.0.4cpe:2.3:a:ibm:powervc:1.2.0.4:*:*:*:standard:*:*:*
Rows per page:
1-10 of 211

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.008

Percentile

81.2%

Related for NVD:CVE-2015-1937