Ibm Hardware Management Console vulnerabilities
17 known vulnerabilities affecting ibm/hardware_management_console.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH6MEDIUM8
Vulnerabilities
Page 1 of 1
CVE-2025-36125MEDIUMCVSS 5.4v10.3.1050.0v11.1.1110.02025-09-09
CVE-2025-36125 [MEDIUM] CWE-79 CVE-2025-36125: IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-si
IBM Hardware Management Console - Power 10.3.1050.0 and 11.1.1110.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2024-45094MEDIUMCVSS 5.4vDS8900FvDS8A002025-05-27
CVE-2024-45094 [MEDIUM] CWE-79 CVE-2024-45094: IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scriptin
IBM DS8900F and DS8A00 Hardware Management Console (HMC) is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
cvelistv5nvd
CVE-2025-1950HIGHCVSS 7.8v10.2.1030.0v10.3.1050.02025-04-22
CVE-2025-1950 [CRITICAL] CWE-114 CVE-2025-1950: IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local us
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.
nvd
CVE-2025-1951MEDIUMCVSS 6.7v10.2.1030.0v10.3.1050.02025-04-22
CVE-2025-1951 [HIGH] CWE-250 CVE-2025-1951: IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local us
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands as a privileged user due to execution of commands with unnecessary privileges.
nvd
CVE-2023-38280HIGHCVSS 7.8v10.1.1010.0v10.2.1030.02023-10-16
CVE-2023-38280 [HIGH] CWE-269 CVE-2023-38280: IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escala
IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.
nvd
CVE-2021-38930HIGHCVSS 7.5vR8.5 88.5x.x.xvR9.1 89.1x.0.0+1 more2022-04-11
CVE-2021-38930 [HIGH] CVE-2021-38930: IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210331.
cvelistv5nvd
CVE-2021-38929HIGHCVSS 7.5vR8.5 88.5x.x.xvR9.1 89.1x.0.0+1 more2022-04-11
CVE-2021-38929 [HIGH] CVE-2021-38929: IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.
IBM System Storage DS8000 Management Console (HMC) R8.5 88.5x.x.x, R9.1 89.1x.0.0, and R9.2 89.2x.0.0 could allow a remote attacker to obtain sensitive information through unpublished URLs. IBM X-Force ID: 210330.
cvelistv5nvd
CVE-2021-29707HIGHCVSS 7.8v9.1.910.0v9.2.950.02021-07-19
CVE-2021-29707 [HIGH] CVE-2021-29707: IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 200879.
nvd
CVE-2016-0230MEDIUMCVSS 6.8v7.9.0v8.1.0+5 more2016-07-07
CVE-2016-0230 [MEDIUM] CWE-264 CVE-2016-0230: IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 throug
IBM Power Hardware Management Console (HMC) 7.3 through 7.3.0 SP7, 7.9 through 7.9.0 SP3, 8.1 through 8.1.0 SP3, 8.2 through 8.2.0 SP2, 8.3 through 8.3.0 SP2, 8.4 through 8.4.0 SP1, and 8.5.0 allows physically proximate attackers to obtain root access via unspecified vectors.
nvd
CVE-2009-1806CRITICALCVSS 9.3v7.3.4.02009-05-28
CVE-2009-1806 [CRITICAL] CVE-2009-1806: Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sharing is used, has unknown impact and attack vectors, related to a shared memory partition and a shared memory pool with redundant paging Virtual I/O Server (VIOS) partitions. NOTE: some of these details are obtained from third party information.
nvd
CVE-2009-0178CRITICALCVSS 10.0v7.3.2.02009-01-20
CVE-2009-0178 [CRITICAL] CVE-2009-0178: Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown i
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 has unknown impact and attack vectors.
nvd
CVE-2008-5035MEDIUMCVSS 5.0v3.2.0v3.3.02008-11-10
CVE-2008-5035 [MEDIUM] CWE-399 CVE-2008-5035: The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release
The Resource Monitoring and Control (RMC) daemon in IBM Hardware Management Console (HMC) 7 release 3.2.0 SP1 and 3.3.0 SP2 allows remote attackers to cause a denial of service (daemon crash or hang) via a packet with an invalid length.
nvd
CVE-2008-0495HIGHCVSS 7.8v7.3.2.02008-01-30
CVE-2008-0495 [HIGH] CVE-2008-0495: Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.
Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2007-6293CRITICALCVSS 10.0v6.1.32007-12-10
CVE-2007-6293 [CRITICAL] CVE-2007-6293: Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 6 R1.3 allow attackers to gain privileges via "some HMC commands."
nvd
CVE-2007-6294MEDIUMCVSS 4.9v3.3.72007-12-10
CVE-2007-6294 [MEDIUM] CWE-264 CVE-2007-6294: Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 3 R3.7 allow attackers
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 3 R3.7 allow attackers to gain privileges via "some HMC commands."
nvd
CVE-2007-6305MEDIUMCVSS 4.6v7.3.2.02007-12-10
CVE-2007-6305 [MEDIUM] CWE-119 CVE-2007-6305: Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 7 R3.2.0 allow attacke
Multiple unspecified vulnerabilities in IBM Hardware Management Console (HMC) 7 R3.2.0 allow attackers to gain privileges via "some HMC commands."
nvd
CVE-2005-0539MEDIUMCVSS 4.6v4.1v4.22005-05-02
CVE-2005-0539 [MEDIUM] CVE-2005-0539: Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows
Unknown vulnerability in IBM Hardware Management Console (HMC) before 4.4 for POWER5 servers allows local users to gain privileges, related to the Guided Setup Wizard.
nvd