Known vulnerabilities in IBM Power Hardware Management Console (HMC) - page 9
Vendor:
IBM Corporation
Software CPE:
cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
202
Public exploits:
22
Known exploited (KEV):
4
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
11.1.1112.1
10.3.1064.1
11.1.1111.3
11.1.1111.2
11.1.1111.1
11.1.1112.0
10.3.1064.0
11.1.1111.5
10.3.1063.2
11.1.1111.4
11.1.1111.0
10.3.1063.1
10.3.1060.0 SP3
11.1.1110.0
10.3.1060.0 SP2
10.3.1060.0 SP1
10.2.1040.0 SP3
10.3.1060.0
10.3.1050.0 SP1
10.2.1040.0 SP2
10.3.1050.0
10.1.1020.0 SP3
10.2.1040.0 SP1
10.1.1020.0 SP2
10.1.1020.0
10.2.1040.0
10.2.1030.0 SP1
10.2.1030.0
10.1.1020.0 SP1
9.2.950.0 SP3
Vulnerabilities (202)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83533 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-46589 |
CWE-444 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP1, 10.3.1050.0 | 28.11.2023 |
SB2023112846 SB2023121851 SB2023122831 and 78 more |
||
| #VU83267 - Improper input validation CVE-2023-5676 |
CWE-20 | Low | 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1 | 20.11.2023 |
SB2023112010 SB2023112011 SB2023112726 and 101 more |
||
| #VU82140 - Improper input validation CVE-2023-22067 |
CWE-20 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP2, 10.3.1050.0 SP1 | 17.10.2023 |
SB2023101797 SB2023101924 SB2023101990 and 117 more |
||
| #VU82014 - Permissions, Privileges, and Access Controls CVE-2022-43926 |
CWE-264 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 16.10.2023 |
SB2023101603 |
||
| #VU81800 - Resource Management Errors CVE-2023-42795 |
CWE-399 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP1, 10.3.1050.0 | 10.10.2023 |
SB2023101084 SB2023101122 SB2023101123 and 47 more |
||
| #VU81799 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2023-45648 |
CWE-444 | Medium | 10.1.1020.0 SP3, 10.2.1040.0 SP1, 10.3.1050.0 | 10.10.2023 |
SB2023101084 SB2023101122 SB2023101123 and 47 more |
||
| #VU78901 - Deserialization of Untrusted Data CVE-2022-40609 |
CWE-502 | High | 10.1.1020.0 | 03.08.2023 |
SB2023080307 SB2023080808 SB2023080809 and 56 more |
||
| #VU78414 - Improper input validation CVE-2023-22049 |
CWE-20 | Low | 10.1.1020.0 SP2, 10.2.1040.0 SP1 | 19.07.2023 |
SB2023071985 SB2023071986 SB2023071987 and 164 more |
||
| #VU76417 - Allocation of Resources Without Limits or Throttling CVE-2023-28709 |
CWE-770 | Medium | 10.1.1020.0 SP1, 10.2.1040.0 | 22.05.2023 |
SB2023052235 SB2023053003 SB2023053052 and 35 more |
||
| #VU75264 - Improper input validation CVE-2023-21939 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 179 more |
||
| #VU75266 - Improper input validation CVE-2023-21968 |
CWE-20 | Low | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 179 more |
||
| #VU75267 - Improper input validation CVE-2023-21937 |
CWE-20 | Low | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 184 more |
||
| #VU75260 - Improper input validation CVE-2023-21930 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 191 more |
||
| #VU75261 - Improper input validation CVE-2023-21967 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 189 more |
||
| #VU75262 - Improper input validation CVE-2023-21954 |
CWE-20 | Medium | 10.1.1020.0, 10.2.1040.0 | 18.04.2023 |
SB20230418166 SB20230418167 SB2023041942 and 166 more |
||
| #VU73107 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2023-25690 |
CWE-113 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1040.0 | 07.03.2023 |
SB2023030731 SB2023030862 SB2023030942 and 54 more |
||
| #VU71993 - Information Exposure Through Timing Discrepancy CVE-2022-4304 |
CWE-208 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020767 and 222 more |
||
| #VU71243 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2022-37436 |
CWE-113 | Medium | 10.1.1020.0 SP1, 10.2.1040.0 | 17.01.2023 |
SB2023011740 SB2023011805 SB2023012728 and 33 more |
||
| #VU71242 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-36760 |
CWE-444 | Medium | 10.1.1020.0 SP1, 10.2.1040.0 | 17.01.2023 |
SB2023011740 SB2023011805 SB2023012728 and 33 more |
||
| #VU67545 - Resource Management Errors CVE-2022-2795 |
CWE-399 | Medium | 10.1.1020.0 SP2, 10.2.1040.0 SP1 | 21.09.2022 |
SB2022092131 SB2022092140 SB2022092143 and 71 more |
Showing elements 161 - 180 out of 202