An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.

Project Subscriptions

Vendors Products
Power System E1050 Subscribe
Power System E1080 Subscribe
Power System E950 Subscribe
Power System E980 Subscribe
Power System H922 Subscribe
Power System H924 Subscribe
Power System L1022 Subscribe
Power System L1024 Subscribe
Power System L922 Subscribe
Power System S1014 Subscribe
Power System S1022 Subscribe
Power System S1022s Subscribe
Power System S1024 Subscribe
Power System S914 Subscribe
Power System S922 Subscribe
Power System S924 Subscribe
Powervm Hypervisor Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2023-34856 An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 22 Jan 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-01-22T16:48:02.322Z

Reserved: 2023-04-08T15:56:20.544Z

Link: CVE-2023-30438

cve-icon Vulnrichment

Updated: 2024-08-02T14:21:44.988Z

cve-icon NVD

Status : Modified

Published: 2023-05-17T13:15:09.380

Modified: 2024-11-21T08:00:11.077

Link: CVE-2023-30438

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses