CVE-2023-30438

An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:*
OR cpe:2.3:h:ibm:power_system_e950:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e980:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h922:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_h924:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l922:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s914:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s922:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s924:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_e1080:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:*
cpe:2.3:o:ibm:powervm_hypervisor:*:*:*:*:*:*:*:*
OR cpe:2.3:h:ibm:power_system_e1050:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1022:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_l1024:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1014:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1022s:-:*:*:*:*:*:*:*
cpe:2.3:h:ibm:power_system_s1024:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 8.8
v2 : unknown
v3 : 9.3
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/252706 - VDB Entry, Vendor Advisory () https://exchange.xforce.ibmcloud.com/vulnerabilities/252706 - VDB Entry, Vendor Advisory
References () https://www.ibm.com/support/pages/node/6993021 - Vendor Advisory () https://www.ibm.com/support/pages/node/6993021 - Vendor Advisory

Information

Published : 2023-05-17 13:15

Updated : 2024-11-21 08:00


NVD link : CVE-2023-30438

Mitre link : CVE-2023-30438

CVE.ORG link : CVE-2023-30438


JSON object : View

Products Affected

ibm

  • power_system_h924
  • power_system_e980
  • power_system_s1022s
  • power_system_s914
  • power_system_s1024
  • power_system_e950
  • power_system_h922
  • power_system_s924
  • power_system_l922
  • power_system_e1080
  • power_system_e1050
  • power_system_s1014
  • power_system_s922
  • power_system_s1022
  • power_system_l1022
  • powervm_hypervisor
  • power_system_l1024