Known vulnerabilities in IBM Power Hardware Management Console (HMC) - page 8
Vendor:
IBM Corporation
Software CPE:
cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
185
Public exploits:
21
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.3.1064.1
11.1.1111.3
11.1.1111.2
11.1.1111.1
11.1.1112.0
10.3.1064.0
11.1.1111.5
10.3.1063.2
11.1.1111.4
11.1.1111.0
10.3.1063.1
10.3.1060.0 SP3
11.1.1110.0
10.3.1060.0 SP2
10.3.1060.0 SP1
10.2.1040.0 SP3
10.3.1060.0
10.3.1050.0 SP1
10.2.1040.0 SP2
10.3.1050.0
10.1.1020.0 SP3
10.2.1040.0 SP1
10.1.1020.0 SP2
10.1.1020.0
10.2.1040.0
10.2.1030.0 SP1
10.2.1030.0
10.1.1020.0 SP1
9.2.950.0 SP3
Vulnerabilities (185)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-46589 |
CWE-444 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP1, 10.3.1050.0 | 28.11.2023 |
SB2023112846 SB2023121851 SB2023122831 and 78 more |
||
| #VU83267 - Improper input validation CVE-2023-5676 |
CWE-20 | Low | 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1 | 20.11.2023 |
SB2023112010 SB2023112011 SB2023112726 and 101 more |
||
| #VU82140 - Improper input validation CVE-2023-22067 |
CWE-20 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1 | 17.10.2023 |
SB2023101797 SB2023101924 SB2023101990 and 117 more |
||
| #VU82141 - Improper input validation CVE-2023-22081 |
CWE-20 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1 | 17.10.2023 |
SB2023101797 SB2023101798 SB2023101905 and 187 more |
||
| #VU82014 - Permissions, Privileges, and Access Controls CVE-2022-43926 |
CWE-264 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 16.10.2023 |
SB2023101603 |
||
| #VU81800 - Resource Management Errors CVE-2023-42795 |
CWE-399 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP1, 10.3.1050.0 | 10.10.2023 |
SB2023101084 SB2023101122 SB2023101123 and 47 more |
||
| #VU81799 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-45648 |
CWE-444 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP1, 10.3.1050.0 | 10.10.2023 |
SB2023101084 SB2023101122 SB2023101123 and 47 more |
||
| #VU81728 - Resource exhaustion CVE-2023-44487 |
CWE-400 | High | 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1 | 10.10.2023 |
SB2023101023 SB2023101024 SB2023101037 and 648 more |
||
| #VU78901 - Deserialization of Untrusted Data CVE-2022-40609 |
CWE-502 | High | 10.1.1020.0 | 03.08.2023 |
SB2023080307 SB2023080808 SB2023080809 and 56 more |
||
| #VU78414 - Improper input validation CVE-2023-22049 |
CWE-20 | Low | 10.1.1020.0 SP2, 10.2.1040.0 SP1 | 19.07.2023 |
SB2023071985 SB2023071986 SB2023071987 and 164 more |
||
| #VU76417 - Allocation of Resources Without Limits or Throttling CVE-2023-28709 |
CWE-770 | Medium | 10.1.1020.0 SP1, 10.2.1040.0 | 22.05.2023 |
SB2023052235 SB2023053003 SB2023053052 and 35 more |
||
| #VU75740 - Improper Authentication CVE-2023-2283 |
CWE-287 | High | 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1 | 04.05.2023 |
SB2023050456 SB2023050501 SB2023052441 and 84 more |
||
| #VU75264 - Improper input validation CVE-2023-21939 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 179 more |
||
| #VU75266 - Improper input validation CVE-2023-21968 |
CWE-20 | Low | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 179 more |
||
| #VU75267 - Improper input validation CVE-2023-21937 |
CWE-20 | Low | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 184 more |
||
| #VU75260 - Improper input validation CVE-2023-21930 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 191 more |
||
| #VU75261 - Improper input validation CVE-2023-21967 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 189 more |
||
| #VU75262 - Improper input validation CVE-2023-21954 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 166 more |
||
| #VU71242 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-36760 |
CWE-444 | Medium | 10.1.1020.0 SP1, 10.2.1040.0 | 17.01.2023 |
SB2023011740 SB2023011805 SB2023012728 and 33 more |
||
| #VU67545 - Resource Management Errors CVE-2022-2795 |
CWE-399 | Medium | 10.1.1020.0 SP2, 10.2.1040.0 SP1 | 21.09.2022 |
SB2022092131 SB2022092140 SB2022092143 and 71 more |
Showing elements 141 - 160 out of 185