CVE-2025-36125
- EPSS 0.03%
- Published 09.09.2025 19:27:58
- Last modified 11.09.2025 17:14:25
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionalit...
CVE-2025-1951
- EPSS 0.01%
- Published 22.04.2025 14:48:08
- Last modified 12.08.2025 18:09:11
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.
CVE-2025-1950
- EPSS 0.01%
- Published 22.04.2025 14:46:51
- Last modified 14.08.2025 01:14:00
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.
CVE-2024-56477
- EPSS 0.24%
- Published 14.02.2025 15:15:11
- Last modified 18.08.2025 18:15:31
IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the sy...
CVE-2014-0883
- EPSS 0.18%
- Published 20.04.2018 21:29:00
- Last modified 21.11.2024 02:02:58
IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure...
CVE-2016-5011
- EPSS 0.2%
- Published 11.04.2017 15:59:00
- Last modified 20.04.2025 01:37:25
The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot reco...
CVE-2017-1134
- EPSS 0.05%
- Published 20.03.2017 16:59:01
- Last modified 20.04.2025 01:37:25
IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access. IBM Reference #: 1998459.
CVE-2012-3296
- EPSS 0.58%
- Published 17.08.2012 20:55:04
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspeci...