Boletines de Vulnerabilidades

IBM Security Bulletin: IBM PowerVC is impacted by OpenStack Glance v2 API unrestricted path traversal (CVE-2014-9493, CVE-2015-1195)


Información sobre el sistema

   
Software afectado IBM

Descripción

IBM PowerVC is impacted by OpenStack Glance v2 API unrestricted path traversal vulnerability (CVE-2014-9493, CVE-2015-1195). CVE(s): CVE-2014-9493 and CVE-2015-1195 Affected product(s) and affected version(s): PowerVC Express Edition 1.2.0.0 through 1.2.0.4 PowerVC Express Edition 1.2.1.0 through 1.2.1.2 PowerVC Standard Edition 1.2.0.0 through 1.2.0.4 PowerVC Standard Edition 1.2.1.0 through 1.2.1.2 PowerVC Standard Edition 1.2.2.0 through 1.2.2.2 Refer to the following reference

More info:

https://www-304.ibm.com/connections/blogs/PSIRT/entry/ibm_security_bulletin_ibm_powervc_is_impacted_by_openstack_glance_v2_api_unrestricted_path_traversal_cve_2014_9493_cve_2015_1195?lang=en_us

Identificadores estándar

Propiedad Valor
CVE CVE-2014-9493 ,CVE-2015-1195 ,CVE-2015-0203 ,CVE-2015-0223 ,CVE-2015-0224 ,CVE-2015-1966 ,CVE-2014-8150 and CVE-2015-4000.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2015-07-01

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT