CRITICAL🇵🇱 Wersja polska

CVE-2026-12943

CVSS 9.8v3.1pub. 2026-07-30upd. 2026-08-10

IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • IBM Hardware Management Console

    APP
    Ibm
    10.3.1050.0 – 10.3.1064.1 (excl.)11.1.1110.0 – 11.1.1112.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2025-1950CRITICAL9.3PL ✓same product

IBM Hardware Management Console — wykonanie poleceń przez niezaufane biblioteki

CVE-2025-1951HIGH8.4same product

IBM Hardware Management Console - Power Systems V10.2.1030.0 and V10.3.1050.0 could allow a local user to exec...

CVE-2023-38280HIGH8.4same product

IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their p...

CVE-2021-29707HIGH7.8same product

IBM HMC (Hardware Management Console) V9.1.910.0 and V9.2.950.0 could allow a local user to escalate their pri...

CVE-2009-1806HIGH9.3same product

Unspecified vulnerability in IBM Hardware Management Console (HMC) 7 release 3.4.0 SP2, when Active Memory Sha...