Required CVE Record Information
Description
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.
References 6 Total
- exchange.xforce.ibmcloud.com: ibm-hmc-viosvrcmd-priv-escalation(75906) vdb-entry
- ibm.com: MB03580 vendor-advisory
- ibm.com: MB03554 vendor-advisory
- ibm.com: MB03550 vendor-advisory
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_power_hmc_viosrvcmd_command_allows_elevated_privilege_on_vios_cve_2012_218825
- ibm.com: MB03548 vendor-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 6 Total
- exchange.xforce.ibmcloud.com: ibm-hmc-viosvrcmd-priv-escalation(75906) vdb-entryx_transferred
- ibm.com: MB03580 vendor-advisoryx_transferred
- ibm.com: MB03554 vendor-advisoryx_transferred
- ibm.com: MB03550 vendor-advisoryx_transferred
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_power_hmc_viosrvcmd_command_allows_elevated_privilege_on_vios_cve_2012_218825 x_transferred
- ibm.com: MB03548 vendor-advisoryx_transferred