Known vulnerabilities in IBM Power Hardware Management Console (HMC) - page 10
Vendor:
IBM Corporation
Software CPE:
cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
202
Public exploits:
22
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
11.1.1112.1
10.3.1064.1
11.1.1111.3
11.1.1111.2
11.1.1111.1
11.1.1112.0
10.3.1064.0
11.1.1111.5
10.3.1063.2
11.1.1111.4
11.1.1111.0
10.3.1063.1
10.3.1060.0 SP3
11.1.1110.0
10.3.1060.0 SP2
10.3.1060.0 SP1
10.2.1040.0 SP3
10.3.1060.0
10.3.1050.0 SP1
10.2.1040.0 SP2
10.3.1050.0
10.1.1020.0 SP3
10.2.1040.0 SP1
10.1.1020.0 SP2
10.1.1020.0
10.2.1040.0
10.2.1030.0 SP1
10.2.1030.0
10.1.1020.0 SP1
9.2.950.0 SP3
Vulnerabilities (202)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU72427 - Allocation of Resources Without Limits or Throttling CVE-2023-24998 |
CWE-770 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 20.02.2023 |
SB2023022046 SB2023022047 SB2023030917 and 203 more |
||
| #VU71996 - Double Free CVE-2022-4450 |
CWE-415 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020771 and 180 more |
||
| #VU71995 - Use After Free CVE-2023-0215 |
CWE-416 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 209 more |
||
| #VU71992 - Type confusion CVE-2023-0286 |
CWE-843 | High | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 223 more |
||
| #VU71236 - Untrusted Search Path CVE-2022-4883 |
CWE-426 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 17.01.2023 |
SB2023011734 SB2023011737 SB2023011806 and 38 more |
||
| #VU71235 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-44617 |
CWE-835 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 17.01.2023 |
SB2023011734 SB2023011737 SB2023011806 and 34 more |
||
| #VU71234 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-46285 |
CWE-835 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 17.01.2023 |
SB2023011734 SB2023011737 SB2023011806 and 35 more |
||
| #VU68858 - Off-by-one Error CVE-2021-46848 |
CWE-193 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 31.10.2022 |
SB2022103141 SB2022103142 SB2022103143 and 84 more |
||
| #VU68844 - Type confusion CVE-2022-3676 |
CWE-843 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 31.10.2022 |
SB2022103129 SB2022111110 SB2022111724 and 60 more |
||
| #VU68718 - Use After Free CVE-2022-43680 |
CWE-416 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 25.10.2022 |
SB2022102560 SB2022102566 SB2022103010 and 99 more |
||
| #VU68437 - Improper input validation CVE-2022-21628 |
CWE-20 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 138 more |
||
| #VU68438 - Improper input validation CVE-2022-21626 |
CWE-20 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 157 more |
||
| #VU68441 - Improper input validation CVE-2022-21624 |
CWE-20 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 142 more |
||
| #VU68442 - Improper input validation CVE-2022-21619 |
CWE-20 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 140 more |
||
| #VU67971 - Use After Free CVE-2022-42012 |
CWE-416 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 | 06.10.2022 |
SB2022100645 SB2022100708 SB2022102733 and 57 more |
||
| #VU67970 - Out-of-bounds read CVE-2022-42011 |
CWE-125 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 | 06.10.2022 |
SB2022100645 SB2022100708 SB2022102733 and 57 more |
||
| #VU67969 - Reachable Assertion CVE-2022-42010 |
CWE-617 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 | 06.10.2022 |
SB2022100645 SB2022100708 SB2022102733 and 58 more |
||
| #VU64079 - Missing release of memory after effective lifetime CVE-2022-1012 |
CWE-401 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1 | 08.06.2022 |
SB2022060827 SB2022061417 SB2022062437 and 75 more |
||
| #VU62399 - Improper input validation CVE-2022-21426 |
CWE-20 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1 | 19.04.2022 |
SB2022041944 SB2022041945 SB2022042102 and 129 more |
||
| #VU53778 - NULL Pointer Dereference CVE-2020-13950 |
CWE-476 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1 | 03.06.2021 |
SB2021060320 SB2021060321 SB2021060713 and 15 more |
Showing elements 181 - 200 out of 202