IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power environments (HMC and Novalink) could allow an unauthenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input.
IBM strongly recommends addressing the vulnerability now. The following fixes are available on IBM Fix Central at:
V10R3
https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V10R3&platform=All
https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V10R3&platform=All
V11R1
https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~9100HMCppc&release=V11R1&platform=All
https://www.ibm.com/support/fixcentral/main/selectFixes?parent=powersysmgmntcouncil&product=ibm~hmc~vHMC&release=V11R1&platform=All
Product
Affected Version(s)
VRMF
APAR
Remediation/Fix
Power HMC
V10.3.1050.0 - V10.3.1064.0
V10.3.1064.1 x86
MB04527
MF71762
Power HMC
V10.3.1050.0 - V10.3.1064.0
V10.3.1064.1 ppc
MB04528
MF71763
Power HMC
V11.1.1110.0 - V11.1.1112.0
V11.1.1112.1 x86
MB04529
MF71764
Power HMC
V11.1.1110.0 - V11.1.1112.0
V11.1.1112.1 ppc
MB04530
MF71765