CVE-2023-30438
Summary
| CVE | CVE-2023-30438 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-05-17 13:15:00 UTC |
| Updated | 2023-05-25 19:35:00 UTC |
| Description | An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Ibm | Powervm Hypervisor | All | All | All | All |
| Hardware | Ibm | Power System E1050 | - | All | All | All |
| Hardware | Ibm | Power System E1080 | - | All | All | All |
| Hardware | Ibm | Power System E950 | - | All | All | All |
| Hardware | Ibm | Power System E980 | - | All | All | All |
| Hardware | Ibm | Power System H922 | - | All | All | All |
| Hardware | Ibm | Power System H924 | - | All | All | All |
| Hardware | Ibm | Power System L1022 | - | All | All | All |
| Hardware | Ibm | Power System L1024 | - | All | All | All |
| Hardware | Ibm | Power System L922 | - | All | All | All |
| Hardware | Ibm | Power System S1014 | - | All | All | All |
| Hardware | Ibm | Power System S1022 | - | All | All | All |
| Hardware | Ibm | Power System S1022s | - | All | All | All |
| Hardware | Ibm | Power System S1024 | - | All | All | All |
| Hardware | Ibm | Power System S914 | - | All | All | All |
| Hardware | Ibm | Power System S922 | - | All | All | All |
| Hardware | Ibm | Power System S924 | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: This Power System update is being released to address CVE 2023-30438 | MISC | www.ibm.com | |
| IBM X-Force Exchange | MISC | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.