CVE-2014-0897
low
CVSS v3
—
CVSS v2
3.5
VIR risk
3.5
Description
The Configuration Patterns component in IBM Flex System Manager (FSM) 1.2.0.x, 1.2.1.x, 1.3.0.x, and 1.3.1.x uses a weak algorithm in an encryption step during Chassis Management Module (CMM) account creation, which makes it easier for remote authenticated users to defeat cryptographic protection mechanisms via unspecified vectors.
Predictions
Exploit likelihood
20%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@us.ibm.com — http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096153
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| ibm | flex_system_manager | 1.2.0 | |
| ibm | flex_system_manager | 1.2.1 | |
| ibm | flex_system_manager | 1.3.0 | |
| ibm | flex_system_manager | 1.3.1 | |
References
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT03824
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096153
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91395
- http://www-01.ibm.com/support/docview.wss?uid=swg1IT03824
- http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096153
- https://exchange.xforce.ibmcloud.com/vulnerabilities/91395
CWEs
CWE-310
Verify integrity in audit chain (admin only). AS-IS.