CVE Vulnerabilities

CVE-2023-38280

Improper Privilege Management

Published: Oct 16, 2023 | Modified: Oct 19, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

IBM HMC (Hardware Management Console) 10.1.1010.0 and 10.2.1030.0 could allow a local user to escalate their privileges to root access on a restricted shell. IBM X-Force ID: 260740.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Hardware_management_console Ibm 10.1.1010.0 (including) 10.1.1010.0 (including)
Hardware_management_console Ibm 10.2.1030.0 (including) 10.2.1030.0 (including)

Potential Mitigations

References