Known vulnerabilities in PowerVM NovaLink - page 6
Vendor:
IBM Corporation
Software:
PowerVM NovaLink
Software CPE:
cpe:2.3:a:ibm_corporation:powervm_novalink:*:*:*:*:*:*:*:*
Website:
https://www.ibm.com/us-en
Total vulnerabilities:
114
Public exploits:
4
Known exploited (KEV):
1
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
2.2.1.1-260708
2.3.3-260714
2.3.3
2.3.2-260422
2.2.1.1-260428
2.1.1-260428
2.3.2
2.1.1-260119
2.2.1.1-260119
2.3.2-260116
2.3.1
2.3.1-251007
2.2.1.1-251007
2.1.1-251007
2.3.0.1-250610
2.2.1.1-250529
2.1.1-250528
2.0.0.0
2.2.1.1
2.2.1
2.2.0
2.3.0.1
2.3.0
2.3.0.1-252403
2.2.1.1-252403
2.1.1-250324
2.3.0-250103
2.2.1.1-250103
2.1.1-250103
2.2.1-240917
2.1.1-240913
2.2.1-240626
2.1.1-240625
2.0.3.1-240625
2.2.0-240415
2.1.1-240415
2.1.1
2.1.0
2.2.0-240119
2.1.1-240119
2.0.3.1.1-230926_4635
2.1.1-230921_4631
2.0.1-230626
2.1.1-230725
2.0.3.1.1-230726
2.1.1-230424
2.0.3.1.1-230413
2.0.1-230412
2.1.0-230209
2.0.3.1.1-230127
2.0.1-230201
2.0.3.1.1-221121
2.0.1-220923
2.0.3.1.1-220923
2.0.3.1
2.0.3
2.0.2.1
2.0.2
2.0.1
2.0
Vulnerabilities (114)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU70797 - Exposure of sensitive information to an unauthorized actor CVE-2022-45787 |
CWE-200 | Low | 2.0.1-230412, 2.0.3.1.1-230413, 2.1.1-230424 | 09.01.2023 |
SB2023010909 SB2023020878 SB2023031107 and 34 more |
||
| #VU70444 - Server-Side Request Forgery (SSRF) CVE-2022-46364 |
CWE-918 | Medium | 2.0.1-230412, 2.0.3.1.1-230413, 2.1.1-230424 | 20.12.2022 |
SB2022122009 SB2023011329 SB2023011707 and 67 more |
||
| #VU69670 - Improper input validation CVE-2022-3509 |
CWE-20 | Medium | 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209 | 29.11.2022 |
SB2022111433 SB2022112934 SB2023011787 and 58 more |
||
| #VU69293 - Improper input validation CVE-2022-3171 |
CWE-20 | Medium | 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209 | 14.11.2022 |
SB2022111433 SB2022111440 SB2022112934 and 105 more |
||
| #VU69209 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2022-34165 |
CWE-444 | Medium | 2.0.1-220923, 2.0.3.1.1-220923 | 10.11.2022 |
SB2022111029 SB2022111104 SB2022111409 and 58 more |
||
| #VU68437 - Improper input validation CVE-2022-21628 |
CWE-20 | Medium | 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 138 more |
||
| #VU68438 - Improper input validation CVE-2022-21626 |
CWE-20 | Medium | 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 157 more |
||
| #VU68441 - Improper input validation CVE-2022-21624 |
CWE-20 | Low | 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 142 more |
||
| #VU68442 - Improper input validation CVE-2022-21619 |
CWE-20 | Low | 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209 | 18.10.2022 |
SB2022101901 SB2022101902 SB2022102012 and 140 more |
||
| #VU67948 - Resource exhaustion CVE-2022-37734 |
CWE-400 | Medium | 2.0.1-220923, 2.0.3.1.1-221121 | 05.10.2022 |
SB2022100553 SB2022100555 SB2022100650 and 19 more |
||
| #VU65906 - Exposure of sensitive information to an unauthorized actor CVE-2022-22393 |
CWE-200 | Low | - | 01.08.2022 |
SB2022080110 SB2022081039 SB2022081515 and 8 more |
||
| #VU65845 - Authentication Bypass by Spoofing CVE-2022-22476 |
CWE-290 | Medium | - | 28.07.2022 |
SB2022072816 SB2022080903 SB2022082228 and 29 more |
||
| #VU65486 - Improper input validation CVE-2022-24839 |
CWE-20 | Medium | 2.0.1-220923, 2.0.3.1.1-220923 | 20.07.2022 |
SB2022072038 SB2022102803 SB2022102807 and 31 more |
||
| #VU52252 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2021-29425 |
CWE-22 | Low | 2.0.1-230201, 2.0.3.1.1-230127, 2.1.0-230209 | 15.04.2021 |
SB2021041510 SB2021081922 SB2021093016 and 121 more |
Showing elements 101 - 120 out of 114