CVE-2015-1950
IBM PowerVC Standard Edition 1.2.2.1-1.2.2.2 - Unauthenticated Credential Exposure via Python Interpreter Access
Title source: llmDescription
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
http://www-01.ibm.com/support/docview.wss?uid=nas8N1020740
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/75102
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=swg1IT08926
Scores
EPSS
0.0036
EPSS Percentile
28.0%
Details
CWE
CWE-255
Status
published
Products (2)
ibm/powervc
1.2.2.1
ibm/powervc
1.2.2.2
Published
Jul 01, 2015
Tracked Since
Feb 18, 2026