CVE-2015-1950

IBM PowerVC Standard Edition 1.2.2.1-1.2.2.2 - Unauthenticated Credential Exposure via Python Interpreter Access

Title source: llm
STIX 2.1

Description

IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75102
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT08926

Scores

EPSS 0.0036
EPSS Percentile 28.0%

Details

CWE
CWE-255
Status published
Products (2)
ibm/powervc 1.2.2.1
ibm/powervc 1.2.2.2
Published Jul 01, 2015
Tracked Since Feb 18, 2026