← Back

Integrated Management Module Firmware

integrated_management_module_firmware

Vendor: Ibm • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ibm
1Integrated Management Module Firmware
Nov 21, 2024
Apr 25, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to gen...Show more
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.Show less
1Ibm
1Integrated Management Module Firmware
Nov 21, 2024
Apr 25, 2018
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an...Show more
The TPM on Integrated Management Module II (IMM2) on IBM Flex System x222 servers with firmware 1.00 through 3.56 allows remote attackers to obtain sensitive key information or cause a denial of service by leveraging an incorrect configuration. IBM X-Force ID: 91146.Show less
2Ibm
Lenovo
2Integrated Management Module Firmware
Integrated Management Module Firmware
May 13, 2026
Jun 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote com...Show more
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command data may contain clear text login information. Authorized users that can capture and export FFDC service log data may have access to these remote commands.Show less
1Ibm
6Advanced Management Module
Advanced Management Module FirmwareIntegrated Management Module+3 more
May 6, 2026
Jul 7, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2...Show more
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.Show less