IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to execute commands locally due to improper validation of libraries of an untrusted source.
The system does not properly verify the origin or integrity of loaded libraries, allowing a local user to substitute a library from an untrusted source. When the application loads such a library, the code contained in it is executed in the context of the IBM HMC process. This mechanism enables bypassing normal privilege restrictions and gaining control over the system.
An attacker with local access can execute arbitrary system commands, leading to complete compromise of confidentiality, integrity, and availability of the Power infrastructure management system.
Apply patches available from the vendor in accordance with references published at https://www.ibm.com/support/pages/node/7231507.
IBM Hardware Management Console - Power Systems in versions V10.2.1030.0 and V10.3.1050.0.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HIBM Hardware Management Console
APPIbm10.2.1030.010.3.1050.0
Related vulnerabilities
IBM HMC — nieuwierzytelniony command injection z podwyższonymi uprawnieniami
IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to exec...
IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their p...
IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their pri...
Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sha...