Vulnerability Bulletins

IBM Security Bulletin: IBM PowerVC - Ceilometer DB2/MongoDB Backend Password Leak (CVE-2013-6384)

   
Affected software IBM
 
The password for the database backends is logged at INFO level in the ceilometer-api logs. CVE(s): CVE-2013-6384 Affected product(s) and affected version(s): PowerVC Express Edition 1.2.0.0 PowerVC Standard Edition 1.2.0.0 Refer to the following reference URLs for remediation and additional vulnerability details: Source Bulletin: http://www-01.ibm.com/support/docview.wss?uid=nas8N1020585 X-Force Database: http://xforce.iss.net/xforce/xfdb/89183

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_powervc_ceilometer_db2_mongodb_backend_password_leak_cve_2013_6384?lang=en_us