CVE-2013-5424
IBM Flex System Manager 1.3.0 - Unauthenticated Privilege Escalation via Expired Password Bypass
Title source: llmDescription
IBM Flex System Manager (FSM) 1.3.0 allows remote attackers to bypass intended access restrictions, and create new user accounts or execute tasks, by leveraging an expired password for the system-level account.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87486
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5093938
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IC96952
Scores
EPSS
0.0131
EPSS Percentile
67.6%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/flex_system_manager
1.3.0
Published
Oct 25, 2013
Tracked Since
Feb 18, 2026