Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2010-2656IBM Advanced Management Module vulnerability

CWE-2644 documents4 sources
Severity
5.0MEDIUMNVD
EPSS
17.2%
top 4.97%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 8
Latest updateMay 17

Description

The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-2424-x5j2-7rx4: The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 42022-05-17
CVEList
CVE-2010-2656: The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 42010-07-07

💥Exploits & PoCs

1
Exploit-DB
IBM Bladecenter Management - Multiple Web Application Vulnerabilities2010-07-06
CVE-2010-2656 — IBM vulnerability | cvebase