CVE-2014-0882

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
25/04/2018
Last modified:
04/06/2018

Description

Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:ibm:integrated_management_module_firmware:3.50:*:*:*:*:*:*:*
cpe:2.3:o:ibm:integrated_management_module_firmware:3.55:*:*:*:*:*:*:*
cpe:2.3:o:ibm:integrated_management_module_firmware:3.56:*:*:*:*:*:*:*
cpe:2.3:o:ibm:integrated_management_module_firmware:3.65:*:*:*:*:*:*:*
cpe:2.3:o:ibm:integrated_management_module_firmware:3.67:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_manager_7955:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_manager_8731:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x220:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x240:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:flex_system_x440:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:nextscale_nx360_m4:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x_idataplex_dx360_m4:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3100_m4:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3250_m4:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:system_x3500_m4:-:*:*:*:*:*:*:*