Known vulnerabilities in PowerVM NovaLink - page 2
Vendor:
IBM Corporation
Software:
PowerVM NovaLink
Software CPE:
cpe:2.3:a:ibm_corporation:powervm_novalink:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
114
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
2.2.1.1-260708
2.3.3-260714
2.3.3
2.3.2-260422
2.2.1.1-260428
2.1.1-260428
2.3.2
2.1.1-260119
2.2.1.1-260119
2.3.2-260116
2.3.1
2.3.1-251007
2.2.1.1-251007
2.1.1-251007
2.3.0.1-250610
2.2.1.1-250529
2.1.1-250528
2.0.0.0
2.2.1.1
2.2.1
2.2.0
2.3.0.1
2.3.0
2.3.0.1-252403
2.2.1.1-252403
2.1.1-250324
2.3.0-250103
2.2.1.1-250103
2.1.1-250103
2.2.1-240917
2.1.1-240913
2.2.1-240626
2.1.1-240625
2.0.3.1-240625
2.2.0-240415
2.1.1-240415
2.1.1
2.1.0
2.2.0-240119
2.1.1-240119
2.0.3.1.1-230926_4635
2.1.1-230921_4631
2.0.1-230626
2.1.1-230725
2.0.3.1.1-230726
2.1.1-230424
2.0.3.1.1-230413
2.0.1-230412
2.1.0-230209
2.0.3.1.1-230127
2.0.1-230201
2.0.3.1.1-221121
2.0.1-220923
2.0.3.1.1-220923
2.0.3.1
2.0.3
2.0.2.1
2.0.2
2.0.1
2.0
Vulnerabilities (114)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU135090 - Improper Privilege Management CVE-2026-3621 |
CWE-269 | Medium | 2.2.1.1, 2.3.3 | 24.06.2026 |
SB2026062429 SB2026062430 SB20260626104 and 8 more |
||
| #VU128401 - Improper Encoding or Escaping of Output CVE-2026-34479 |
CWE-116 | Medium | 2.2.1.1, 2.3.3 | 28.04.2026 |
SB20260428217 SB20260513128 SB2026052632 and 13 more |
||
| #VU126765 - Improper input validation CVE-2026-22007 |
CWE-20 | Low | 2.2.1.1, 2.3.3 | 22.04.2026 |
SB20260422123 SB20260422124 SB20260422125 and 70 more |
||
| #VU124875 - Use of Hard-coded Cryptographic Key CVE-2025-14923 |
CWE-321 | Low | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 06.04.2026 |
SB2026040626 SB2026040627 SB2026041006 and 14 more |
||
| #VU124833 - Server-Side Request Forgery (SSRF) CVE-2026-1561 |
CWE-918 | Low | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 02.04.2026 |
SB2026040252 SB2026040325 SB2026040331 and 9 more |
||
| #VU124831 - Weak Password Requirements CVE-2025-14917 |
CWE-521 | Low | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 02.04.2026 |
SB2026040252 SB2026040327 SB2026040328 and 12 more |
||
| #VU124829 - Exposure of sensitive information to an unauthorized actor CVE-2025-14915 |
CWE-200 | Low | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 02.04.2026 |
SB2026040252 SB2026040326 SB2026040329 and 9 more |
||
| #VU124825 - Improperly Controlled Modification of Object Prototype Attributes (\'Prototype Pollution\') CVE-2026-29063 |
CWE-1321 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 02.04.2026 |
SB2026040246 SB2026040612 SB2026040627 and 29 more |
||
| #VU123913 - Improper Access Control CVE-2024-29371 |
CWE-284 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 12.03.2026 |
SB2026031212 SB2026031213 SB2026031310 and 27 more |
||
| #VU122748 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-14914 |
CWE-22 | Low | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 12.02.2026 |
SB2026021209 SB2026021210 SB2026021212 and 22 more |
||
| #VU121727 - Improper input validation CVE-2026-21945 |
CWE-20 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 96 more |
||
| #VU121728 - Improper input validation CVE-2026-21932 |
CWE-20 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 77 more |
||
| #VU121729 - Improper input validation CVE-2026-21933 |
CWE-20 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 89 more |
||
| #VU121730 - Out-of-bounds read CVE-2026-21925 |
CWE-125 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 20.01.2026 |
SB20260120152 SB20260120153 SB20260120154 and 91 more |
||
| #VU120231 - Improper Validation of Certificate with Host Mismatch CVE-2025-68161 |
CWE-297 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 22.12.2025 |
SB2025122245 SB2026012084 SB2026012087 and 98 more |
||
| #VU119901 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CVE-2025-12635 |
CWE-79 | Medium | 2.1.1-260428, 2.2.1.1-260428, 2.3.2-260422 | 12.12.2025 |
SB2025121283 SB2025121517 SB2025121518 and 42 more |
||
| #VU114346 - Command injection CVE-2025-7962 |
CWE-77 | Medium | 2.1.1-260119, 2.2.1.1-260119, 2.3.2-260116 | 21.08.2025 |
SB2025082145 SB2025082146 SB2025082147 and 54 more |
||
| #VU114006 - Privilege Chaining CVE-2025-36124 |
CWE-268 | High | 2.1.1-251007, 2.2.1.1-251007, 2.3.1-251007 | 13.08.2025 |
SB2025081354 SB2025082918 SB2025082921 and 23 more |
||
| #VU113607 - Uncontrolled Recursion CVE-2025-48924 |
CWE-674 | Medium | 2.1.1-251007, 2.2.1.1-251007, 2.3.1-251007 | 04.08.2025 |
SB2025080422 SB2025080423 SB2025080427 and 177 more |
||
| #VU83992 - Use of Insufficiently Random Values CVE-2020-36732 |
CWE-330 | Medium | 2.1.1-260119, 2.2.1.1-260119, 2.3.2-260116 | 08.12.2023 |
SB2023120804 SB2024030742 SB2025091116 and 26 more |
Showing elements 21 - 40 out of 114