Vulnerabilities > IBM > Power Hardware Management Console

DATE CVE VULNERABILITY TITLE RISK
2018-04-20 CVE-2014-0883 Cross-site Scripting vulnerability in IBM Power Hardware Management Console
IBM Power HMC 7.1.0 through 7.8.0 and 7.3.5 is vulnerable to cross-site scripting.
network
low complexity
ibm CWE-79
6.1
2017-04-11 CVE-2016-5011 The parse_dos_extended function in partitions/dos.c in the libblkid library in util-linux allows physically proximate attackers to cause a denial of service (memory consumption) via a crafted MSDOS partition table with an extended partition boot record at zero offset.
local
low complexity
kernel redhat ibm
4.9
2017-03-20 CVE-2017-1134 Local Privilege Escalation vulnerability in IBM Tivoli System Automation for Multiplatforms
IBM Reliable Scalable Cluster Technology could allow a local user to escalate their privileges to gain root access.
local
low complexity
ibm
7.2
2012-08-17 CVE-2012-3296 Cross-Site Scripting vulnerability in IBM Power Hardware Management Console 7R7.1.0/7R7.2.0/7R7.3.0
Cross-site scripting (XSS) vulnerability in the Help link in the login panel in IBM Power Hardware Management Console (HMC) 7R7.1.0 before SP4, 7R7.2.0 before SP2, and 7R7.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
ibm CWE-79
4.3