Known vulnerabilities in IBM Power Hardware Management Console (HMC)
Vendor:
IBM Corporation
Software CPE:
cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
185
Public exploits:
21
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.3.1064.1
11.1.1111.3
11.1.1111.2
11.1.1111.1
11.1.1112.0
10.3.1064.0
11.1.1111.5
10.3.1063.2
11.1.1111.4
11.1.1111.0
10.3.1063.1
10.3.1060.0 SP3
11.1.1110.0
10.3.1060.0 SP2
10.3.1060.0 SP1
10.2.1040.0 SP3
10.3.1060.0
10.3.1050.0 SP1
10.2.1040.0 SP2
10.3.1050.0
10.1.1020.0 SP3
10.2.1040.0 SP1
10.1.1020.0 SP2
10.1.1020.0
10.2.1040.0
10.2.1030.0 SP1
10.2.1030.0
10.1.1020.0 SP1
9.2.950.0 SP3
Vulnerabilities (185)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU131182 - Improper input validation CVE-2026-41293 |
CWE-20 | Medium | 10.3.1064.1, 11.1.1112.0 | 12.05.2026 |
SB2026051281 SB2026051592 SB2026052607 and 20 more |
||
| #VU125743 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-24880 |
CWE-444 | Medium | 10.3.1064.1, 11.1.1112.0 | 09.04.2026 |
SB20260409109 SB20260417131 SB20260422214 and 18 more |
||
| #VU123159 - Incorrect Calculation of Buffer Size CVE-2026-1188 |
CWE-131 | High | 10.3.1063.2, 11.1.1111.5 | 24.02.2026 |
SB2026022412 SB2026022413 SB2026022531 and 46 more |
||
| #VU122999 - Improper Authorization CVE-2026-24734 |
CWE-285 | Medium | 10.3.1063.2, 11.1.1111.5 | 17.02.2026 |
SB2026021766 SB2026030536 SB2026031245 and 24 more |
||
| #VU122998 - Improper Authorization CVE-2025-66614 |
CWE-285 | High | 10.3.1063.2, 11.1.1111.5 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 16 more |
||
| #VU122997 - Protection Mechanism Failure CVE-2026-24733 |
CWE-693 | Low | 10.3.1063.2, 11.1.1111.5 | 17.02.2026 |
SB2026021765 SB2026031245 SB2026031361 and 9 more |
||
| #VU122082 - Out-of-bounds write CVE-2025-69419 |
CWE-787 | Low | 10.3.1064.0, 11.1.1112.0 | 27.01.2026 |
SB2026012785 SB2026012791 SB2026012792 and 67 more |
||
| #VU121727 - Improper input validation CVE-2026-21945 |
CWE-20 | Medium | 10.3.1063.2, 11.1.1111.5 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 96 more |
||
| #VU121729 - Improper input validation CVE-2026-21933 |
CWE-20 | Medium | 10.3.1063.2, 11.1.1111.5 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 89 more |
||
| #VU121730 - Out-of-bounds read CVE-2026-21925 |
CWE-125 | Medium | 10.3.1063.2, 11.1.1111.5 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 91 more |
||
| #VU121425 - Resource Management Errors CVE-2025-71085 |
CWE-399 | Low | 10.3.1064.0, 11.1.1112.0 | 14.01.2026 |
SB2026011476 SB2026020972 SB2026020973 and 97 more |
||
| #VU120834 - Integer overflow CVE-2022-50865 |
CWE-190 | Low | 10.3.1063.2, 11.1.1111.5 | 30.12.2025 |
SB20251230279 SB2026020210 SB2026020211 and 13 more |
||
| #VU120607 - Stack-based buffer overflow CVE-2025-68615 |
CWE-121 | Critical | 10.3.1063.2, 11.1.1111.5 | 26.12.2025 |
SB20251226349 SB2026010785 SB2026011301 and 43 more |
||
| #VU119149 - Improper Neutralization of Server-Side Includes (SSI) Within a Web Page CVE-2025-58098 |
CWE-97 | Low | 10.3.1063.2, 11.1.1111.5 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025121940 and 46 more |
||
| #VU119147 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CVE-2025-65082 |
CWE-74 | Low | 10.3.1063.2, 11.1.1111.5 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025122202 and 32 more |
||
| #VU119146 - Improper input validation CVE-2025-66200 |
CWE-20 | Low | 10.3.1063.2, 11.1.1111.5 | 04.12.2025 |
SB2025120441 SB2025121923 SB2025122202 and 30 more |
||
| #VU118665 - Use After Free CVE-2025-61662 |
CWE-416 | Low | 10.3.1064.0, 11.1.1112.0 | 21.11.2025 |
SB2025112110 SB2025112111 SB2025112122 and 28 more |
||
| #VU117682 - Resource exhaustion CVE-2025-61795 |
CWE-400 | Medium | 10.3.1063.2, 11.1.1111.5 | 27.10.2025 |
SB2025102749 SB20251031122 SB20251031123 and 39 more |
||
| #VU116213 - Out-of-bounds write CVE-2025-9230 |
CWE-787 | Medium | 10.3.1063.2, 11.1.1111.5 | 01.10.2025 |
SB2025100119 SB2025100132 SB2025100133 and 107 more |
||
| #VU20844 - Protection Mechanism Failure CVE-2019-10086 |
CWE-693 | Low | 10.3.1064.0, 11.1.1112.0 | 04.09.2019 |
SB2019090405 SB2019090406 SB2019121902 and 112 more |
Showing elements 1 - 20 out of 185