← Back

CVE-2015-1937

nvd nist
Published: May 30, 2015Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

IBM PowerVC 1.2.0.x through 1.2.0.4, 1.2.1.x through 1.2.1.2, and 1.2.2.x through 1.2.2.2 does not require authentication for the ceilometer NoSQL database, which allows remote attackers to read or write to arbitrary database records, and consequently obtain administrator privileges, via a session on port 27017.

Affected (21)

Products: Ibm: Powervc
1 product
Powervc
Configuration A
21 vulnerable
Vulnerable SoftwareAffected Versions
Ibm
Version 1.2.0.0
Version 1.2.0.0
Version 1.2.0.1
Version 1.2.0.1
Version 1.2.0.2
Version 1.2.0.2
Version 1.2.0.3
Version 1.2.0.3
Version 1.2.0.4
Version 1.2.0.4
Version 1.2.1.0
Version 1.2.1.0
Version 1.2.1.1
Version 1.2.1.2
Version 1.2.1.2
Version 1.2.2.0
Version 1.2.2.0
Version 1.2.2.1
Version 1.2.2.1
Version 1.2.2.2
Version 1.2.2.2

References (6)

Source: psirt@us.ibm.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.