Vulnerability Description
Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via vectors related to generated Service Advisor data (FFDC). IBM X-Force ID: 91149.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Integrated Management Module Firmware | 3.50 |
| Ibm | Flex System Manager 7955 | - |
| Ibm | Flex System Manager 8731 | - |
| Ibm | Flex System X220 | - |
| Ibm | Flex System X240 | - |
| Ibm | Flex System X440 | - |
| Ibm | Nextscale Nx360 M4 | - |
| Ibm | System X Idataplex Dx360 M4 | - |
| Ibm | System X3100 M4 | - |
| Ibm | System X3250 M4 | - |
| Ibm | System X3500 M4 | - |
| Ibm | System X3530 M4 | - |
| Ibm | System X3550 M4 | - |
| Ibm | System X3630 M4 | - |
| Ibm | System X3650 M4 | - |
| Ibm | System X3750 M4 | - |
Related Weaknesses (CWE)
References
- https://support.lenovo.com/us/en/solutions/ht114525Third Party Advisory
- https://www.ibm.com/blogs/psirt/security-bulletin-account-specific-information-lVendor Advisory
- https://www.ibm.com/support/home/docdisplay?lndocid=MIGR-5094726Vendor Advisory
- https://support.lenovo.com/us/en/solutions/ht114525Third Party Advisory
- https://www.ibm.com/blogs/psirt/security-bulletin-account-specific-information-lVendor Advisory
- https://www.ibm.com/support/home/docdisplay?lndocid=MIGR-5094726Vendor Advisory
FAQ
What is CVE-2014-0882?
CVE-2014-0882 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Integrated Management Module II (IMM2) on IBM Flex System, NeXtScale, System x3xxx, and System x iDataPlex systems might allow remote authenticated users to obtain sensitive account information via ve...
How severe is CVE-2014-0882?
CVE-2014-0882 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-0882?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Integrated Management Module Firmware, Ibm Flex System Manager 7955, Ibm Flex System Manager 8731, Ibm Flex System X220, Ibm Flex System X240.