Known vulnerabilities in PowerVM Hypervisor
Vendor:
IBM Corporation
Software:
PowerVM Hypervisor
Software CPE:
cpe:2.3:a:ibm_corporation:powervm_hypervisor:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
19
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
Vulnerabilities (19)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU113442 - Out-of-bounds read CVE-2025-49133 |
CWE-125 | Low | FW1050.41 | 30.07.2025 |
SB2025073028 SB2025073029 SB2025073030 and 24 more |
||
| #VU112444 - Out-of-bounds read CVE-2025-52497 |
CWE-125 | Medium | FW1060.52, FW1110.10 | 07.07.2025 |
SB2025070782 SB2025070784 SB2025070785 and 3 more |
||
| #VU112443 - Covert Timing Channel CVE-2025-49087 |
CWE-385 | Medium | FW1060.52, FW1110.10 | 07.07.2025 |
SB2025070782 SB2026012742 |
||
| #VU111030 - Out-of-bounds read CVE-2025-2884 |
CWE-125 | Low | FW1050.41 | 11.06.2025 |
SB2025061103 SB2025061303 SB2025072845 and 3 more |
||
| #VU103600 - Covert Timing Channel CVE-2024-13176 |
CWE-385 | Medium | FW950.D1, FW950.E0, FW1050.31, FW1050.40, FW1060.31, FW1060.40 | 04.02.2025 |
SB2025020454 SB2025020456 SB2025020656 and 58 more |
||
| #VU86287 - Exposure of sensitive information to an unauthorized actor CVE-2023-46183 |
CWE-200 | Low | FW950.A0, FW1020.50, FW1030.40, FW1050.00 | 09.02.2024 |
SB2024020910 |
||
| #VU86059 - Exposure of sensitive information to an unauthorized actor CVE-2023-33851 |
CWE-200 | Low | FW950.A0, FW1020.50, FW1030.40, FW1050.00 | 05.02.2024 |
SB2024020521 |
||
| #VU77543 - Improper input validation CVE-2023-30438 |
CWE-20 | Medium | FW950.71, FW1010.51, FW1020.31 | 20.06.2023 |
SB2023062013 |
||
| #VU77293 - Memory corruption CVE-2021-3746 |
CWE-119 | Medium | FW1010.40 | 14.06.2023 |
SB2023061426 SB2022060240 SB2021090933 and 2 more |
||
| #VU77192 - Cryptographic Issues CVE-2014-0076 |
CWE-310 | Low | FW950.60 | 13.06.2023 |
SB2023061323 SB2014042110 SB2014040806 and 1 more |
||
| #VU77191 - Improper input validation CVE-2009-3245 |
CWE-20 | High | FW950.60 | 13.06.2023 |
SB2023061323 |
||
| #VU77160 - Exposure of sensitive information to an unauthorized actor CVE-2023-25683 |
CWE-200 | Medium | FW1020.31 | 12.06.2023 |
SB2023061223 |
||
| #VU76483 - Improper input validation CVE-2023-30440 |
CWE-20 | Low | FW860.B3, FW950.71, FW1010.51, FW1020.31, FW1030.11 | 24.05.2023 |
SB2023052431 |
||
| #VU72707 - Out-of-bounds read CVE-2023-1018 |
CWE-125 | Medium | FW1010.60, FW1020.40 | 02.03.2023 |
SB2023030207 SB2023030210 SB2023030758 and 17 more |
||
| #VU72706 - Out-of-bounds write CVE-2023-1017 |
CWE-787 | High | FW1010.60, FW1020.40 | 02.03.2023 |
SB2023030207 SB2023030210 SB2023030758 and 16 more |
||
| #VU65383 - Permissions, Privileges, and Access Controls CVE-2022-22445 |
CWE-264 | Low | FW950.40, FW1010.32 | 18.07.2022 |
SB2022071811 |
||
| #VU61391 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2022-0778 |
CWE-835 | Medium | FW950.40, FW1010.32 | 15.03.2022 |
SB2022031520 SB2022031522 SB2022031611 and 238 more |
||
| #VU54502 - Insufficient Entropy CVE-2021-3505 |
CWE-331 | Low | FW1050.00 | 01.07.2021 |
SB2021070126 SB2024030110 SB2022092385 and 1 more |
||
| #VU15723 - Information Exposure Through Timing Discrepancy CVE-2018-5407 |
CWE-208 | Low | FW950.60 | 06.11.2018 |
SB2018110602 SB2018111301 SB2018112201 and 30 more |