Known vulnerabilities in IBM Hardware Management Console
Vendor:
IBM Corporation
Software:
IBM Hardware Management Console
Software CPE:
cpe:2.3:a:ibm_corporation:ibm_hardware_management_console:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
16
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (16)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU67029 - Error Handling CVE-2021-41041 |
CWE-388 | Low | 9.2.953.0, 10.1.1020.0 | 06.09.2022 |
SB2022090642 SB2022090643 SB2022093005 and 25 more |
||
| #VU64079 - Missing release of memory after effective lifetime CVE-2022-1012 |
CWE-401 | Medium | 9.2.950.0 SP3 ppc, 9.2.950.0 SP3 x86, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86 | 08.06.2022 |
SB2022060827 SB2022061417 SB2022062437 and 75 more |
||
| #VU63668 - Exposure of sensitive information to an unauthorized actor CVE-2021-45485 |
CWE-200 | Medium | 9.2.950.0 SP3 ppc, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86 | 25.05.2022 |
SB2022022237 SB2022062928 SB2022062931 and 26 more |
||
| #VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-0778 |
CWE-835 | Medium | OP940.40, 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 15.03.2022 |
SB2022031520 SB2022031522 SB2022031611 and 238 more |
||
| #VU59730 - Improper input validation CVE-2022-21293 |
CWE-20 | Medium | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 18.01.2022 |
SB2022011840 SB2022011841 SB2022011931 and 95 more |
||
| #VU59731 - Improper input validation CVE-2022-21294 |
CWE-20 | Medium | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 18.01.2022 |
SB2022011840 SB2022011841 SB2022011931 and 96 more |
||
| #VU59733 - Improper input validation CVE-2022-21341 |
CWE-20 | Medium | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 18.01.2022 |
SB2022011840 SB2022011841 SB2022011931 and 96 more |
||
| #VU59734 - Improper input validation CVE-2022-21248 |
CWE-20 | Low | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 18.01.2022 |
SB2022011840 SB2022011841 SB2022011931 and 95 more |
||
| #VU59057 - Server-Side Request Forgery (SSRF) CVE-2021-44224 |
CWE-918 | Medium | 9.2.950.0 SP3 ppc, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86 | 20.12.2021 |
SB2021122005 SB2021122021 SB2021122709 and 33 more |
||
| #VU57752 - Resource exhaustion CVE-2021-25219 |
CWE-400 | Medium | 9.2.950.0 SP3 ppc, 9.2.950.0 SP3 x86, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86 | 28.10.2021 |
SB2021102801 SB2021102903 SB2021110111 and 33 more |
||
| #VU56681 - NULL Pointer Dereference CVE-2021-34798 |
CWE-476 | Medium | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 17.09.2021 |
SB2021091706 SB2021091707 SB2021092301 and 44 more |
||
| #VU56679 - Memory corruption CVE-2021-39275 |
CWE-119 | Medium | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 17.09.2021 |
SB2021091706 SB2021091707 SB2021092301 and 44 more |
||
| #VU56474 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2021-33193 |
CWE-444 | Medium | 9.2.950.0 SP3 ppc, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86 | 13.09.2021 |
SB2021091317 SB2021091707 SB2021092301 and 24 more |
||
| #VU56064 - Out-of-bounds read CVE-2021-3712 |
CWE-125 | Medium | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 24.08.2021 |
SB2021082414 SB2021082508 SB2021082510 and 142 more |
||
| #VU53778 - NULL Pointer Dereference CVE-2020-13950 |
CWE-476 | Medium | 9.2.950.0 SP3 ppc, 9.2.950.0 SP3 x86, 10.1.1020.0 SP1 ppc, 10.1.1020.0 SP1 x86 | 03.06.2021 |
SB2021060320 SB2021060321 SB2021060713 and 15 more |
||
| #VU52734 - Reachable Assertion CVE-2021-25214 |
CWE-617 | Low | 9.2.952.0, 10.1.1010.0 x86, 10.1.1010.0 ppc | 29.04.2021 |
SB2021042903 SB2021042904 SB2021042928 and 25 more |