CVE-2013-5424

IBM Flex System Manager 1.3.0 - Unauthenticated Privilege Escalation via Expired Password Bypass

Title source: llm
STIX 2.1

Description

IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by leveraging an expired password for the system-level account.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87486
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC96952

Scores

EPSS 0.0131
EPSS Percentile 67.6%

Details

CWE
CWE-264
Status published
Products (1)
ibm/flex_system_manager 1.3.0
Published Oct 25, 2013
Tracked Since Feb 18, 2026