This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Ibm First view 2009-04-13
Product Bladecenter Last view 2014-01-20
Version Type Hardware
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:h:ibm:bladecenter:hs23e:*:*:*:*:*:*:* 4
cpe:2.3:h:ibm:bladecenter:hs23:*:*:*:*:*:*:* 4
cpe:2.3:h:ibm:bladecenter:hs22v:*:*:*:*:*:*:* 3
cpe:2.3:h:ibm:bladecenter:hx5:*:*:*:*:*:*:* 3
cpe:2.3:h:ibm:bladecenter:hs22:*:*:*:*:*:*:* 3
cpe:2.3:h:ibm:bladecenter:js12:*:7998:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:s:*:1948:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hc10:*:7996:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:ls20:*:8850:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs20:*:1883:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:t:*:8720:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:e:*:1881:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:qs21:*:0792:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:ls21:*:7971:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:h:*:7989:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs21:*:8853:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:t:*:8730:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:e:*:8677:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs12:*:1916:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:js21:*:7988:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:ls41:*:7972:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs21_xm:*:7995:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs12:*:8014:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs21_xm:*:1915:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:ht:*:8740:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs12:*:8028:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:js21:*:8844:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:js22:*:7998:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:s:*:8886:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:h:*:8852:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:hs21:*:1885:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:e:*:7967:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:qs22:*:0793:*:*:*:*:* 2
cpe:2.3:h:ibm:bladecenter:ht:*:8750:*:*:*:*:* 2

Related : CVE

  Date Alert Description
4.3 2014-01-20 CVE-2013-4030

Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic.

4 2013-08-09 CVE-2013-4038

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file.

4.3 2013-08-09 CVE-2013-4037

The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.

10 2013-08-09 CVE-2013-4031

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.

4 2009-04-13 CVE-2009-1289

private/login.ssi in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allows remote attackers to discover the access roles and scopes of arbitrary user accounts via a modified WEBINDEX parameter.

4.3 2009-04-13 CVE-2009-1288

Multiple cross-site scripting (XSS) vulnerabilities in the Advanced Management Module (AMM) on the IBM BladeCenter, including the BladeCenter H with BPET36H 54, allow remote attackers to inject arbitrary web script or HTML via (1) the username in a login action or (2) the PATH parameter to private/file_management.ssi in the File manager.

CWE : Common Weakness Enumeration

%idName
40% (2) CWE-310 Cryptographic Issues
20% (1) CWE-255 Credentials Management
20% (1) CWE-200 Information Exposure
20% (1) CWE-79 Failure to Preserve Web Page Structure ('Cross-site Scripting')

Open Source Vulnerability Database (OSVDB)

id Description
53659 IBM BladeCenter Advanced Management Module Admin Interface Arbitrary User Per...
53658 IBM BladeCenter Advanced Management Module private/file_management.ssi PATH P...
53657 IBM BladeCenter Advanced Management Module Login username XSS