CVE-2025-36125
- EPSS 0.03%
- Published 09.09.2025 19:27:58
- Last modified 11.09.2025 17:14:25
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionalit...
CVE-2024-45094
- EPSS 0.05%
- Published 27.05.2025 22:41:38
- Last modified 09.06.2025 18:51:17
IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially l...
CVE-2025-1951
- EPSS 0.01%
- Published 22.04.2025 14:48:08
- Last modified 12.08.2025 18:09:11
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.
CVE-2025-1950
- EPSS 0.01%
- Published 22.04.2025 14:46:51
- Last modified 14.08.2025 01:14:00
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.
CVE-2023-38280
- EPSS 0.03%
- Published 16.10.2023 02:15:47
- Last modified 21.11.2024 08:13:13
IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.
CVE-2021-29707
- EPSS 0.04%
- Published 19.07.2021 16:15:08
- Last modified 21.11.2024 06:01:40
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.
CVE-2016-0230
- EPSS 0.08%
- Published 07.07.2016 14:59:00
- Last modified 12.04.2025 10:46:40
IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root acces...
CVE-2009-1806
- EPSS 0.5%
- Published 28.05.2009 20:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shared memory partition and a shared memory pool with redundant paging Vir...
- EPSS 0.99%
- Published 20.01.2009 16:30:00
- Last modified 09.04.2025 00:30:58
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.
- EPSS 1.83%
- Published 10.11.2008 16:15:12
- Last modified 09.04.2025 00:30:58
The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.