Where
-Infinity
0
Severity
9.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

IBM PowerVM Hypervisor could allow a privileged user to gain access to another VM due to assigning duplicate WWPNs.

1 / 2
Source: IBM
First published (updated )
Severity
8.4
Integer Overflow
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call to inject an arbitrary amount of data into hypervisor or partition memory, resulting in either a crash causing a full platform re-IPL and terminating all hosted partitions, or corruption of hypervisor or partition memory. The PowerVM hypervisor will restart automatically; however, repeated exploitation could result in a sustained availability impact. Successful exploitation results in an integrity and availability impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
Severity
8.2
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can send a specially crafted mailbox message to read or modify arbitrary regions of Hostboot memory, compromising the host firmware boot stack and the hypervisor subsequently loaded by it. Successful exploitation results in a confidentiality, integrity, and availability impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
Severity
7.5
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM PowerVM Hypervisor could allow an attacker to obtain sensitive information if they gain service access to the FSP.

1 / 2
First published (updated )
Severity
7.3
Out-of-bounds Read
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the PowerVM hypervisor call interface. An attacker with root access to a guest partition can issue a specially crafted hypervisor call causing a virtual processor to become permanently unresponsive, requiring a full platform re-IPL to restore normal operation. In some cases this may also cause the guest to inject a small amount of data into hypervisor or partition memory with no attacker control over the target location. Successful exploitation results in an integrity and availability impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
Severity
6.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

IBM PowerVM Hypervisor could allow an authenticated user to cause the system to crash using a specially crafted IBMi Hypervisor call.

1 / 2
Source: IBM
First published (updated )
Severity
6.7
AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H

IBM PowerVM Hypervisor FW950.00 through FW950.E0, FW1050.00 through FW1050.50, and FW1060.00 through FW1060.40 could allow a local privileged user to cause a denial of service by issuing a specially crafted IBM i hypervisor call that would disclose memory contents or consume excessive memory resources.

1 / 2
Source: MITRE

Remedy

Customers with the products below should install 950.E1(950_182)/950.F0(950_192) or newer to remediate this vulnerability. Power 9 * IBM Power System L922 (9008-22L) * IBM Power System S922 (9009-22A, 9009-22G) * IBM Power System H922 (9223-22H, 9223-22S) * IBM Power System S914 (9009-41A, 9009-41G) * IBM Power System S924 (9009-42A, 9009-42G) * IBM Power System H924 (9223-42H, 9223-42S) * IBM Power System E950 (9040-MR9) * IBM Power System E980 (9080-M9S) Customers with the products below should install FW1050.51(1050_095)/FW1050.60(1050_090), FW1060.41(1060_120), or newer to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX)   Customers with the products below should install FW1050.51(1050_113)/FW1050.60(1050_108), FW1060.41(1060_120), or newer to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B)
First published (updated )
Severity
6.2
AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 use persistent storage key seeds that result in an AES key with reduced strength. An attacker with access to the service processor or HMC could exploit this weakness to derive the encryption key and access the data.

1 / 2
Source: MITRE
First published (updated )
Severity
6
AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with administrative privileges to decrypt encrypted data due to certain hypervisor calls utilizing less entropy than requested.

1 / 2
Source: MITRE
First published (updated )
Severity
4.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

The PowerVM Logical Partition Mobility(LPM) (PowerVM Hypervisor FW920, FW930, FW940, and FW950) encryption key exchange protocol can be compromised. If an attacker has the ability to capture encrypted LPM network traffic and is able to gain service access to the FSP they can use this information to perform a series of PowerVM service procedures to decrypt the captured migration traffic IBM X-Force ID: 198232

1 / 2
First published (updated )
First published (updated )
Advisory
IBM-7257555
Severity
3.3
AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

IBM PowerVM Hypervisor FW1110.00 through FW1110.03, FW1060.00 through FW1060.51, and FW950.00 through FW950.F0 may expose a limited amount of data to a peer partition in specific shared processor configurations during certain operations.

1 / 2
Source: MITRE

Remedy

Customers with the products below should install FW1110.10(1110_100), or newer to remediate this vulnerability. Power 11 * IBM Power System E1180 (9080-HEU) Customers with the products below should install FW1110.10(1110_116), or newer to remediate this vulnerability. Power 11 * IBM Power System S1122 (9824-22A) * IBM Power System S1124 (9824-42A) * IBM Power System S1122s (9824-22B) * IBM Power System S1114 (9824-41B) * IBM Power System L1122 (9856-22H) * IBM Power System L1124 (9856-42H) * IBM Power System E1150 (9043-MRU) Customers with the products below should install FW1060.52(1060_153)/FW1060.60(1060_158), or newer to remediate this vulnerability. Power 10 * IBM Power System E1080 (9080-HEX) Customers with the products below should install FW1060.52(1060_149), FW1060.60(1060_157), or newer to remediate this vulnerability. Power 10 * IBM Power System S1022 (9105-22A) * IBM Power System S1024 (9105-42A) * IBM Power System S1022s (9105-22B) * IBM Power System S1014 (9105-41B) * IBM Power System L1022 (9786-22H) * IBM Power System L1024 (9786-42H) * IBM Power System E1050 (9043-MRX) * IBM Power System S1012 (9028-21B)  Customers with the products below should install 950.F1(950_194)/950.G0(950_203), or newer to remediate this vulnerability. Power 9 * IBM Power System L922 (9008-22L) * IBM Power System S922 (9009-22A, 9009-22G) * IBM Power System H922 (9223-22H, 9223-22S) * IBM Power System S914 (9009-41A, 9009-41G) * IBM Power System S924 (9009-42A, 9009-42G) * IBM Power System H924 (9223-42H, 9223-42S) * IBM Power System E950 (9040-MR9) * IBM Power System E980 (9080-M9S)
First published (updated )
First published (updated )
Advisory
IBM-7257556
Severity
6
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

IBM PowerVM Hypervisor could allow a local user with administration privileges to obtain sensitive information from a Virtual TPM through a series of PowerVM service procedures.

1 / 2
Source: IBM

Remedy

IBM strongly recommends addressing the vulnerability now by upgrading to IBM Concert Software 2.2.0 Download IBM Concert Software 2.2.0 from Container software library section of IBM Entitled Registry ( ICR https://myibm.ibm.com/products-services/containerlibrary ) and follow installation instructions https://www.ibm.com/docs/en/concert  depending on the type of deployment.
First published (updated )
First published (updated )
Advisory
IBM-7280632
Severity
4.6
AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 could allow an attacker with physical access to the Transparent Memory Encryption (TME) hardware to decrypt encrypted memory due to insufficient cryptographic entropy.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7280628
Severity
8.4
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

A carefully crafted OS hypervisor call can cause the PowerVM hypervisor to crash or compromise OS memory integrity.

1 / 2
Source: IBM
First published (updated )
First published (updated )
Advisory
IBM-7283228
Severity
6
AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H

IBM PowerVM could allow a local attacker to obtain sensitive information or cause a denial of service due to improper control of format strings.

1 / 2
Source: IBM
First published (updated )
First published (updated )
Advisory
IBM-7283238
Severity
7.3
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in host firmware configuration parsing. An attacker with authenticated service-level access to the service processor can write specially crafted configuration data, causing the host firmware boot stack to crash with possible memory corruption during system initialisation, resulting in an integrity and availability impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7283234
Severity
8.8
Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition performing a network boot can prevent that partition from completing its boot sequence. On partitions where OS secure boot is not enabled, which is the default configuration, the attacker can also substitute the boot image, compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7283237
Severity
8.2
Integer Overflow
AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in the service processor mailbox interface. An attacker with authenticated service-level access to the FSP can exploit this vulnerability, allowing arbitrary code to be executed in the host firmware runtime, giving full control over the managed system, resulting in a confidentiality, integrity, and availability impact to the managed system.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7283233
Severity
6.5
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker with access to the same network as a partition undergoing iSCSI SAN network boot can prevent that partition from completing its boot sequence. Other partitions and the managed system are not affected. Only partitions actively performing an iSCSI SAN network boot are affected, resulting in an availability impact.

1 / 2
Source: MITRE
First published (updated )
First published (updated )
Advisory
IBM-7283232
Severity
8.8
AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 Power Systems Firmware is affected by a vulnerability in partition firmware during network boot. An unauthenticated attacker on the same network as a partition undergoing network boot can send a malformed packet, allowing arbitrary code to be executed in the partition firmware and compromising everything subsequently loaded by that partition. Other partitions and the managed system are not affected. Only partitions actively performing a network boot are affected, resulting in a confidentiality, integrity, and availability impact.

1 / 2
Source: MITRE
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203