FTP Credential Leak in IBM PowerVC Express Edition
CVE-2014-4750

Currently unrated

Key Information:

Vendor

IBM

Status
Vendor
CVE Published:
20 August 2014

What is CVE-2014-4750?

IBM PowerVC Express Edition versions prior to FixPack3 have a vulnerability where an FTP session is established for file transfers to managed IVM instances. This insecure implementation allows attackers to potentially intercept and discover sensitive credentials through network sniffing, posing a serious risk to data integrity and system security. Organizations using this version should apply the necessary patches to mitigate the risk associated with unauthorized access.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.