← Back

CVE-2009-1289

nvd nist
Published: Apr 13, 2009Modified: Apr 23, 2026

JSON object

Loading...
4.0
Vector
AV:N/AC:L/Au:S/C:P/I:N/A:N
Exploitability: 8.0 / Impact: 2.9
Source: NVD

Description

private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter.

Affected (30)

2 products
Advanced Management Module
Bladecenter
Configuration A
30 vulnerable
Vulnerable SoftwareAffected Versions
Version 1.36h
Ibm
Version e
Version e
Version e
Version h
Version h
Version hc10
Version hs12
Version hs12
Version hs12
Version hs20
Version hs21
Version hs21
Version hs21_xm
Version hs21_xm
Version ht
Version ht
Version js12
Version js21
Version js21
Version js22
Version ls20
Version ls21
Version ls41
Version qs21
Version qs22
Version s
Version s
Version t
Version t

References (10)

Source: cve@mitre.org
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Exploit
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.