CVE Vulnerabilities

CVE-2023-38280

Improper Privilege Management

Published: Oct 16, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Hardware_management_console Ibm 10.1.1010.0 (including) 10.1.1010.0 (including)
Hardware_management_console Ibm 10.2.1030.0 (including) 10.2.1030.0 (including)

Potential Mitigations

References