IBM PowerVM Hypervisor FW1120.00 至 FW1120.01、FW1110.00 至 FW1110.31 以及 FW1060.00 至 FW1060.81 版本中,在虚拟机监控器调用接口存在一个漏洞。拥有来宾分区根(root)访问权限的攻击者可以读取有限量的虚拟机监控器内存,从而可能暴露属于虚拟机监控器或托管在同一系统中的其他来宾分区的敏感数据,造成机密性损失。攻击者无法控制返回哪些内存内容。在多租户环境中,来宾分区可能运行任意操作系统镜像,因此该漏洞尤其值得重视。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| IBM | PowerVM Hypervisor | FW1120.00 ~ FW1120.01 |
cpe:2.3:a:ibm:powervm_hypervisor:fw1120.00:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-81549 | 9.6 CRITICAL | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-82093 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81552 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81548 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81547 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81545 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-81539 | 8.8 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-77874 | 8.6 HIGH | IBM Enterprise Build of Quarkus is affected by multiple vulnerabilities |
| CVE-2026-82094 | 7.1 HIGH | DataStage on Cloud Pak for Data has several vulnerabilities |
| CVE-2026-6544 | 6.2 MEDIUM | Multiple Vulnerabilities in IBM Concert Software |
| CVE-2026-17413 | 5.1 MEDIUM | This Power System update is being released to address |
| CVE-2026-17503 | 5.1 MEDIUM | This Power System update is being released to address |
| CVE-2026-17504 | 5.1 MEDIUM | This Power System update is being released to address |
| CVE-2026-77825 | 4.9 MEDIUM | IBM ContextForge MCP Gateway is affected by path traversal |
| CVE-2026-18870 | 4.3 MEDIUM | This Power System update is being released to address |
| CVE-2026-17511 | 3.4 LOW | This Power System update is being released to address |
| CVE-2026-18857 | 3.4 LOW | This Power System update is being released to address |
| CVE-2026-18104 | 3.3 LOW | IBM Db2 Mirror for i is vulnerable to obtain sensitive information [] |
No comments yet