SB2022071811 - Improper access control in IBM PowerVM Hypervisor
Published: July 18, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Permissions, Privileges, and Access Controls (CVE-ID: CVE-2022-22445)
The vulnerability allows a remote user to compromise partition firmware.
The vulnerability exists due to application does not properly impose security restrictions. A remote user with service access to the FSP (POWER9 only) or admin authority to a partition can compromise partition firmware.
Remediation
Install update from vendor's website.
References
- https://www.ibm.com/blogs/psirt/security-bulletin-an-attacker-that-gains-service-access-to-the-fsp-power9-only-or-gains-admin-authority-to-a-partition-can-compromise-partition-firmware/"
- https://www.ibm.com/blogs/psirt/security-bulletin-an-attacker-that-gains-service-access-to-the-fsp-power9-only-or-gains-admin-authority-to-a-partition-can-compromise-partition-firmware/</a><br><a
- https://www.ibm.com/support/pages/node/6604071"
- https://www.ibm.com/support/pages/node/6604071</a></p><p><br></p>