Known vulnerabilities in IBM Power Hardware Management Console (HMC) - page 4

Software CPE: cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Total vulnerabilities: 185
Public exploits: 21
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting IBM Power Hardware Management Console (HMC) IBM Power Hardware Management Console (HMC) is affected by 185 known vulnerabilities: 4 critical, 22 high, 107 medium, 52 low Critical High Medium Low

Vulnerabilities (185)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU112130 - Heap-based Buffer Overflow
CVE-2025-2900
CWE-122 High
No
No
10.3.1060.0 SP2 03.07.2025 SB2025070313
SB2025070316
SB2025070318
and 22 more
#VU109938 - Exposure of sensitive information to an unauthorized actor
CVE-2025-46421
CWE-200 Low
No
No
10.3.1060.0 SP2 29.05.2025 SB2025052715
SB20250529101
SB20250529102
and 26 more
#VU109937 - Missing release of memory after effective lifetime
CVE-2025-46420
CWE-401 Low
No
No
10.3.1060.0 SP2 29.05.2025 SB2025052992
SB20250529101
SB20250529102
and 29 more
#VU109936 - Use After Free
CVE-2025-32911
CWE-416 High
No
No
10.3.1060.0 SP2 29.05.2025 SB2025052992
SB2025052997
SB2025052998
and 33 more
#VU109927 - Buffer over-read
CVE-2025-32053
CWE-126 Medium
No
No
10.3.1060.0 SP2 29.05.2025 SB2024111329
SB2025052980
SB2025052994
and 29 more
#VU109838 - NULL Pointer Dereference
CVE-2025-32913
CWE-476 High
No
No
10.3.1060.0 SP2 27.05.2025 SB2025052718
SB2025052723
SB2025052997
and 33 more
#VU109834 - Out-of-bounds read
CVE-2025-32906
CWE-125 Medium
No
No
10.3.1060.0 SP2 27.05.2025 SB2025052715
SB2025052723
SB2025052994
and 37 more
#VU107867 - Process Control
CVE-2025-1950
CWE-114 Medium
No
No
10.2.1040.0 SP3, 10.3.1060.0 SP1 23.04.2025 SB2025042322
#VU107520 - Improper input validation
CVE-2025-21587
CWE-20 Medium
No
No
10.3.1060.0 SP2 16.04.2025 SB20250416145
SB20250416146
SB20250416147
and 103 more
#VU107521 - Improper input validation
CVE-2025-30698
CWE-20 Medium
No
No
10.3.1060.0 SP2 16.04.2025 SB20250416145
SB20250416146
SB20250416147
and 93 more
#VU107482 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-56477
CWE-22 Medium
No
No
10.3.1060.0 SP1 16.04.2025 SB2025041630
#VU105723 - Stack-based buffer overflow
CVE-2024-8176
CWE-121 High
No
No
10.3.1060.0 SP2 14.03.2025 SB2025031426
SB2025031429
SB2025031430
and 105 more
#VU105715 - Out-of-bounds write
CVE-2025-27363
CWE-787 Critical
Available
Exploited
10.2.1040.0 SP3, 10.3.1060.0 SP2 14.03.2025 SB2025031402
SB2025031502
SB2025031750
and 97 more
#VU105485 - Improper input validation
CVE-2025-24813
CWE-20 Critical
Available
Exploited
10.2.1040.0 SP3, 10.3.1060.0 SP1 10.03.2025 SB2025031069
SB2025031976
SB2025032642
and 48 more
#VU104099 - Use After Free
CVE-2024-56171
CWE-416 High
No
No
10.3.1060.0 SP2 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU104098 - Stack-based buffer overflow
CVE-2025-24928
CWE-121 High
No
No
10.3.1060.0 SP2 20.02.2025 SB2025022003
SB2025022010
SB2025022023
and 111 more
#VU100995 - Memory corruption
CVE-2024-52531
CWE-119 Low
No
No
10.2.1040.0 SP3, 10.3.1060.0 SP1 27.11.2024 SB2024111329
SB2024112738
SB2024112739
and 35 more
#VU97948 - Improper input validation
CVE-2023-20584
CWE-20 Low
No
No
10.2.1040.0 SP3, 10.3.1060.0 SP1 02.10.2024 SB2024100225
SB2024100226
SB2024100227
and 18 more
#VU96619 - Permissions, Privileges, and Access Controls
CVE-2023-31315
CWE-264 Low
No
No
10.2.1040.0 SP3, 10.3.1060.0 SP1 29.08.2024 SB2024082927
SB2024082928
SB2024082929
and 23 more
#VU9687 - Memory corruption
CVE-2017-9047
CWE-119 Low
No
No
10.3.1060.0 SP2 19.12.2017 SB2017121308
SB2017111019
SB2022110928
and 29 more


Showing elements 61 - 80 out of 185