CVE-2015-1950
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access…
Does this matter?
Lower severity and a low EPSS score (0.36%). Track it; it rarely justifies an emergency change on its own.
Description
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- ibm/powervc
- Source
- psirt@us.ibm.com
References
- http://www-01.ibm.com/support/docview.wss?uid=nas8N1020740Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT08926
- http://www.securityfocus.com/bid/75102
- http://www-01.ibm.com/support/docview.wss?uid=nas8N1020740Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT08926
- http://www.securityfocus.com/bid/75102
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.