CVE-2012-4856

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:ibm:power_5_system_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_201_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_202_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_219_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_222_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_233_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_258_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_259_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_261_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_284_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_298_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_299_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_320_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_332_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_338_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_358_201:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_371:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_382_382:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_403_382:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_415_382:*:*:*:*:*:*:*
cpe:2.3:o:ibm:power_5_system_firmware:sf240_417:*:*:*:*:*:*:*
OR cpe:2.3:h:ibm:power_5:9110-51a:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9110-510:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9111-285:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9111-520:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9113-550:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9115-505:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9116-561:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9117-570:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9118-575:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9123-710:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9124-720:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9131-52a:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9133-55a:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9405-520:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-520:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-525:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-550:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9406-570:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_5:9407-515:*:*:*:*:*:*:*

History

21 Nov 2024, 01:43

Type Values Removed Values Added
References () http://aix.software.ibm.com/aix/efixes/security/squadrons_advisory.asc - Vendor Advisory () http://aix.software.ibm.com/aix/efixes/security/squadrons_advisory.asc - Vendor Advisory
References () http://www.kb.cert.org/vuls/id/194604 - US Government Resource () http://www.kb.cert.org/vuls/id/194604 - US Government Resource
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/79736 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/79736 -

Information

Published : 2012-12-20 12:02

Updated : 2024-11-21 01:43


NVD link : CVE-2012-4856

Mitre link : CVE-2012-4856

CVE.ORG link : CVE-2012-4856


JSON object : View

Products Affected

ibm

  • power_5_system_firmware
  • power_5
CWE
CWE-255

Credentials Management Errors