Known vulnerabilities in IBM Power Hardware Management Console (HMC) - page 2
Vendor:
IBM Corporation
Software CPE:
cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
185
Public exploits:
21
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.3.1064.1
11.1.1111.3
11.1.1111.2
11.1.1111.1
11.1.1112.0
10.3.1064.0
11.1.1111.5
10.3.1063.2
11.1.1111.4
11.1.1111.0
10.3.1063.1
10.3.1060.0 SP3
11.1.1110.0
10.3.1060.0 SP2
10.3.1060.0 SP1
10.2.1040.0 SP3
10.3.1060.0
10.3.1050.0 SP1
10.2.1040.0 SP2
10.3.1050.0
10.1.1020.0 SP3
10.2.1040.0 SP1
10.1.1020.0 SP2
10.1.1020.0
10.2.1040.0
10.2.1030.0 SP1
10.2.1030.0
10.1.1020.0 SP1
9.2.950.0 SP3
Vulnerabilities (185)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117708 - Out-of-bounds read CVE-2025-11021 |
CWE-125 | Medium | 10.3.1063.1, 11.1.1111.4 | 28.10.2025 |
SB2025102860 SB2025102862 SB2025102864 and 20 more |
||
| #VU117689 - Improper Privilege Management CVE-2025-11561 |
CWE-269 | Medium | 10.3.1063.1, 11.1.1111.4 | 28.10.2025 |
SB2025102811 SB2025102813 SB2025102814 and 35 more |
||
| #VU117483 - Improper input validation CVE-2025-53066 |
CWE-20 | Medium | 10.3.1063.1, 11.1.1111.0 | 22.10.2025 |
SB20251022107 SB20251022108 SB20251022109 and 118 more |
||
| #VU117484 - Improper input validation CVE-2025-53057 |
CWE-20 | Medium | 10.3.1063.1, 11.1.1111.0 | 22.10.2025 |
SB20251022107 SB20251022108 SB20251022109 and 121 more |
||
| #VU116883 - Improper Neutralization of Null Byte or NUL Character CVE-2025-61985 |
CWE-158 | Low | 10.3.1063.2, 11.1.1111.5 | 10.10.2025 |
SB2025101008 SB2025103199 SB20251031100 and 25 more |
||
| #VU116882 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVE-2025-61984 |
CWE-78 | Low | 10.3.1063.2, 11.1.1111.5 | 10.10.2025 |
SB2025101008 SB2025103199 SB20251031100 and 27 more |
||
| #VU115751 - Resource exhaustion CVE-2025-59375 |
CWE-400 | Medium | 10.3.1063.2, 11.1.1111.5 | 17.09.2025 |
SB2025091783 SB2025091789 SB2025091790 and 106 more |
||
| #VU114443 - Session Fixation CVE-2025-55668 |
CWE-384 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 26.08.2025 |
SB2025082650 SB2025082651 SB2025090566 and 15 more |
||
| #VU114093 - Incorrect Calculation CVE-2025-5372 |
CWE-682 | Low | 10.3.1063.2, 11.1.1111.5 | 14.08.2025 |
SB2025081494 SB2025081495 SB2025081532 and 21 more |
||
| #VU114024 - Resource exhaustion CVE-2025-48989 |
CWE-400 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 13.08.2025 |
SB2025081375 SB2025081376 SB20250820127 and 49 more |
||
| #VU112731 - Improper Encoding or Escaping of Output CVE-2024-47252 |
CWE-116 | High | 10.3.1060.0 SP3, 11.1.1110.0 | 10.07.2025 |
SB2025071040 SB2025071764 SB2025072111 and 34 more |
||
| #VU112730 - Security Features CVE-2025-23048 |
CWE-254 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 10.07.2025 |
SB2025071040 SB2025071764 SB2025072111 and 29 more |
||
| #VU112729 - Resource Management Errors CVE-2025-49630 |
CWE-399 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 10.07.2025 |
SB2025071040 SB2025071764 SB2025072111 and 26 more |
||
| #VU112276 - Resource exhaustion CVE-2025-53506 |
CWE-400 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 41 more |
||
| #VU112275 - Resource Management Errors CVE-2025-52520 |
CWE-399 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 42 more |
||
| #VU112274 - Improper input validation CVE-2025-52434 |
CWE-20 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 04.07.2025 |
SB20250704167 SB2025072535 SB2025072536 and 32 more |
||
| #VU111161 - Resource exhaustion CVE-2025-48988 |
CWE-400 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 40 more |
||
| #VU111159 - Improper Protection of Alternate Path CVE-2025-49125 |
CWE-424 | Medium | 10.3.1060.0 SP3, 11.1.1110.0 | 16.06.2025 |
SB2025061634 SB2025061927 SB20250620145 and 35 more |
||
| #VU109946 - Integer overflow CVE-2025-4945 |
CWE-190 | High | 10.3.1063.1, 11.1.1111.4 | 29.05.2025 |
SB2025052993 SB2025053009 SB2025053020 and 27 more |
||
| #VU104035 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2025-26465 |
CWE-300 | Medium | 10.3.1063.1, 11.1.1111.0 | 18.02.2025 |
SB2025021815 SB2025021830 SB2025021833 and 49 more |
Showing elements 21 - 40 out of 185