Unrated severityNVD Advisory· Published Jul 8, 2010· Updated Apr 29, 2026
CVE-2010-2656
CVE-2010-2656
Description
The IBM BladeCenter with Advanced Management Module (AMM) firmware build ID BPET48L, and possibly other versions before 4.7 and 5.0, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download (1) logs or (2) core files via direct requests, as demonstrated by a request for private/sdc.tgz.
Affected products
37cpe:2.3:h:ibm:advanced_management_module:1.00:*:*:*:*:*:*:*+ 36 more
- cpe:2.3:h:ibm:advanced_management_module:1.00:*:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.01:*:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.20:*:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.20:f:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.25:*:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.25:e:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.25:i:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.26:b:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.26:e:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.26:h:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.26:i:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.26:k:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.28:g:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.32:d:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.34:b:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.34:e:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.36:d:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.36:g:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.36:h:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.36:k:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.42:d:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.42:f:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.42:i:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.42:n:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.42:o:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:1.42:t:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.46:c:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.46:j:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.48:c:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.48:d:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.48:g:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.48:n:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.50:c:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.50:g:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.50:k:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:2.50:p:*:*:*:*:*:*
- cpe:2.3:h:ibm:advanced_management_module:*:l:*:*:*:*:*:*range: <=2.48
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- dsecrg.com/pages/vul/show.phpnvdExploit
- www.exploit-db.com/exploits/14237/nvdExploit
- www.securityfocus.com/bid/41383nvdExploit
- osvdb.org/66123nvd
News mentions
0No linked articles in our index yet.