Known vulnerabilities in IBM Power Hardware Management Console (HMC) - page 9
Vendor:
IBM Corporation
Software CPE:
cpe:2.3:a:ibm_corporation:hmc:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
185
Public exploits:
21
Known exploited (KEV):
3
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
10.3.1064.1
11.1.1111.3
11.1.1111.2
11.1.1111.1
11.1.1112.0
10.3.1064.0
11.1.1111.5
10.3.1063.2
11.1.1111.4
11.1.1111.0
10.3.1063.1
10.3.1060.0 SP3
11.1.1110.0
10.3.1060.0 SP2
10.3.1060.0 SP1
10.2.1040.0 SP3
10.3.1060.0
10.3.1050.0 SP1
10.2.1040.0 SP2
10.3.1050.0
10.1.1020.0 SP3
10.2.1040.0 SP1
10.1.1020.0 SP2
10.1.1020.0
10.2.1040.0
10.2.1030.0 SP1
10.2.1030.0
10.1.1020.0 SP1
9.2.950.0 SP3
Vulnerabilities (185)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU73107 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2023-25690 |
CWE-113 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1040.0 | 07.03.2023 |
SB2023030731 SB2023030862 SB2023030942 and 54 more |
||
| #VU72427 - Allocation of Resources Without Limits or Throttling CVE-2023-24998 |
CWE-770 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 20.02.2023 |
SB2023022046 SB2023022047 SB2023030917 and 202 more |
||
| #VU71996 - Double Free CVE-2022-4450 |
CWE-415 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020771 and 180 more |
||
| #VU71995 - Use After Free CVE-2023-0215 |
CWE-416 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 209 more |
||
| #VU71993 - Information Exposure Through Timing Discrepancy CVE-2022-4304 |
CWE-208 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020748 SB2023020767 and 222 more |
||
| #VU71992 - Type confusion CVE-2023-0286 |
CWE-843 | High | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 SP1 | 07.02.2023 |
SB2023020742 SB2023020747 SB2023020748 and 223 more |
||
| #VU71243 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') CVE-2022-37436 |
CWE-113 | Medium | 10.1.1020.0 SP1, 10.2.1040.0 | 17.01.2023 |
SB2023011740 SB2023011805 SB2023012728 and 33 more |
||
| #VU71236 - Untrusted Search Path CVE-2022-4883 |
CWE-426 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 17.01.2023 |
SB2023011734 SB2023011737 SB2023011806 and 38 more |
||
| #VU71235 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-44617 |
CWE-835 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 17.01.2023 |
SB2023011734 SB2023011737 SB2023011806 and 34 more |
||
| #VU71234 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-46285 |
CWE-835 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 17.01.2023 |
SB2023011734 SB2023011737 SB2023011806 and 35 more |
||
| #VU68858 - Off-by-one Error CVE-2021-46848 |
CWE-193 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 31.10.2022 |
SB2022103141 SB2022103142 SB2022103143 and 84 more |
||
| #VU68844 - Type confusion CVE-2022-3676 |
CWE-843 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 31.10.2022 |
SB2022103129 SB2022111110 SB2022111724 and 60 more |
||
| #VU68718 - Use After Free CVE-2022-43680 |
CWE-416 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 25.10.2022 |
SB2022102560 SB2022102566 SB2022103010 and 97 more |
||
| #VU68437 - Improper input validation CVE-2022-21628 |
CWE-20 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 138 more |
||
| #VU68438 - Improper input validation CVE-2022-21626 |
CWE-20 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 157 more |
||
| #VU68441 - Improper input validation CVE-2022-21624 |
CWE-20 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0, 10.2.1030.0 SP1 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 142 more |
||
| #VU67971 - Use After Free CVE-2022-42012 |
CWE-416 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 | 06.10.2022 |
SB2022100645 SB2022100708 SB2022102733 and 57 more |
||
| #VU67970 - Out-of-bounds read CVE-2022-42011 |
CWE-125 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 | 06.10.2022 |
SB2022100645 SB2022100708 SB2022102733 and 57 more |
||
| #VU67969 - Reachable Assertion CVE-2022-42010 |
CWE-617 | Low | 9.2.950.0 SP3, 10.1.1020.0 SP1, 10.2.1030.0 | 06.10.2022 |
SB2022100645 SB2022100708 SB2022102733 and 58 more |
||
| #VU62399 - Improper input validation CVE-2022-21426 |
CWE-20 | Medium | 9.2.950.0 SP3, 10.1.1020.0 SP1 | 19.04.2022 |
SB2022041944 SB2022041945 SB2022042102 and 129 more |
Showing elements 161 - 180 out of 185