Known vulnerabilities in IBM Power Hardware Management Console (HMC) - page 5
Vendor:
IBM Corporation
Software CPE:
cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
202
Public exploits:
22
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
11.1.1112.1
10.3.1064.1
11.1.1111.3
11.1.1111.2
11.1.1111.1
11.1.1112.0
10.3.1064.0
11.1.1111.5
10.3.1063.2
11.1.1111.4
11.1.1111.0
10.3.1063.1
10.3.1060.0 SP3
11.1.1110.0
10.3.1060.0 SP2
10.3.1060.0 SP1
10.2.1040.0 SP3
10.3.1060.0
10.3.1050.0 SP1
10.2.1040.0 SP2
10.3.1050.0
10.1.1020.0 SP3
10.2.1040.0 SP1
10.1.1020.0 SP2
10.1.1020.0
10.2.1040.0
10.2.1030.0 SP1
10.2.1030.0
10.1.1020.0 SP1
9.2.950.0 SP3
Vulnerabilities (202)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU112130 - Heap-based Buffer Overflow CVE-2025-2900 |
CWE-122 | High | 10.3.1060.0 SP2 | 03.07.2025 |
SB2025070313 SB2025070316 SB2025070318 and 22 more |
||
| #VU109938 - Exposure of sensitive information to an unauthorized actor CVE-2025-46421 |
CWE-200 | Low | 10.3.1060.0 SP2 | 29.05.2025 |
SB2025052715 SB20250529101 SB20250529102 and 26 more |
||
| #VU109937 - Missing release of memory after effective lifetime CVE-2025-46420 |
CWE-401 | Low | 10.3.1060.0 SP2 | 29.05.2025 |
SB2025052992 SB20250529101 SB20250529102 and 29 more |
||
| #VU109838 - NULL Pointer Dereference CVE-2025-32913 |
CWE-476 | High | 10.3.1060.0 SP2 | 27.05.2025 |
SB2025052718 SB2025052723 SB2025052997 and 33 more |
||
| #VU107867 - Process Control CVE-2025-1950 |
CWE-114 | Medium | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 23.04.2025 |
SB2025042322 |
||
| #VU107520 - Improper input validation CVE-2025-21587 |
CWE-20 | Medium | 10.3.1060.0 SP2 | 16.04.2025 |
SB20250416145 SB20250416146 SB20250416147 and 103 more |
||
| #VU107521 - Improper input validation CVE-2025-30698 |
CWE-20 | Medium | 10.3.1060.0 SP2 | 16.04.2025 |
SB20250416145 SB20250416146 SB20250416147 and 93 more |
||
| #VU107482 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2024-56477 |
CWE-22 | Medium | 10.3.1060.0 SP1 | 16.04.2025 |
SB2025041630 |
||
| #VU105723 - Stack-based buffer overflow CVE-2024-8176 |
CWE-121 | High | 10.3.1060.0 SP2 | 14.03.2025 |
SB2025031426 SB2025031429 SB2025031430 and 105 more |
||
| #VU105715 - Out-of-bounds write CVE-2025-27363 |
CWE-787 | Critical | 10.2.1040.0 SP3, 10.3.1060.0 SP2 | 14.03.2025 |
SB2025031402 SB2025031502 SB2025031750 and 97 more |
||
| #VU105485 - Improper input validation CVE-2025-24813 |
CWE-20 | Critical | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 10.03.2025 |
SB2025031069 SB2025031976 SB2025032642 and 48 more |
||
| #VU104099 - Use After Free CVE-2024-56171 |
CWE-416 | High | 10.3.1060.0 SP2 | 20.02.2025 |
SB2025022003 SB2025022010 SB2025022023 and 111 more |
||
| #VU104098 - Stack-based buffer overflow CVE-2025-24928 |
CWE-121 | High | 10.3.1060.0 SP2 | 20.02.2025 |
SB2025022003 SB2025022010 SB2025022023 and 111 more |
||
| #VU100995 - Memory corruption CVE-2024-52531 |
CWE-119 | Low | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 27.11.2024 |
SB2024111329 SB2024112738 SB2024112739 and 35 more |
||
| #VU97951 - Incomplete cleanup CVE-2023-31356 |
CWE-459 | Low | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 02.10.2024 |
SB2024100225 SB2024100226 SB2024100227 and 19 more |
||
| #VU97948 - Improper input validation CVE-2023-20584 |
CWE-20 | Low | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 02.10.2024 |
SB2024100225 SB2024100226 SB2024100227 and 18 more |
||
| #VU96619 - Permissions, Privileges, and Access Controls CVE-2023-31315 |
CWE-264 | Low | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 29.08.2024 |
SB2024082927 SB2024082928 SB2024082929 and 23 more |
||
| #VU84028 - Reliance on Undefined, Unspecified, or Implementation-Defined Behavior CVE-2023-20592 |
CWE-758 | Low | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 08.12.2023 |
SB2023120815 SB2023120817 SB2023120818 and 24 more |
||
| #VU79525 - Protection Mechanism Failure CVE-2022-46329 |
CWE-693 | Low | 10.2.1040.0 SP3, 10.3.1060.0 SP1 | 15.08.2023 |
SB2023081532 SB2023092004 SB2023092005 and 18 more |
||
| #VU9687 - Memory corruption CVE-2017-9047 |
CWE-119 | Low | 10.3.1060.0 SP2 | 19.12.2017 |
SB2017121308 SB2017111019 SB2022110928 and 29 more |
Showing elements 81 - 100 out of 202