Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-56477
Disclosure Date: February 14, 2025 (last updated February 15, 2025)
IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2021-29891
Disclosure Date: August 19, 2022 (last updated October 08, 2023)
IBM OPENBMC OP910 and OP940 could allow a privileged user to upload an improper site identity certificate that may cause it to lose network services. IBM X-Force ID: 207221.
0
Attacker Value
Unknown
CVE-2021-38960
Disclosure Date: February 02, 2022 (last updated October 07, 2023)
IBM OPENBMC OP920, OP930, and OP940 could allow an unauthenticated user to obtain sensitive information. IBM X-Force ID: 212047.
0
Attacker Value
Unknown
CVE-2021-29847
Disclosure Date: December 14, 2021 (last updated October 07, 2023)
BMC firmware (IBM Power System S821LC Server (8001-12C) OP825.50) configuration changed to allow an authenticated user to open an insecure communication channel which could allow an attacker to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 205267.
0
Attacker Value
Unknown
CVE-2014-0883
Disclosure Date: April 20, 2018 (last updated November 09, 2023)
IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 91163.
0
Attacker Value
Unknown
CVE-2016-5011
Disclosure Date: April 11, 2017 (last updated November 26, 2024)
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
0
Attacker Value
Unknown
CVE-2017-1134
Disclosure Date: March 20, 2017 (last updated November 26, 2024)
IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.
0
Attacker Value
Unknown
CVE-2012-3296
Disclosure Date: August 17, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-2188
Disclosure Date: August 06, 2012 (last updated October 04, 2023)
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.
0