CVE-2015-1890

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
06/04/2015
Last modified:
12/04/2025

Description

/usr/lpp/mmfs/bin/gpfs.snap in IBM General Parallel File System (GPFS) 4.1 before 4.1.0.7 produces an archive potentially containing cleartext keys, and lacks a warning about reviewing this archive to detect included keys, which might allow remote attackers to obtain sensitive information by leveraging access to a technical-support data stream.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:ibm:general_parallel_file_system:4.1:*:*:*:*:*:*:*