VYPR

PowerVM VIOS

by IBM

CVEs (16)

  • CVE-2026-16816CriAug 19, 2026
    risk 0.64cvss 9.9epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-16656CriAug 19, 2026
    risk 0.64cvss 9.8epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to gain root privileges due to improper authentication.

  • CVE-2026-15068CriAug 19, 2026
    risk 0.64cvss 9.9epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

  • CVE-2026-15065CriAug 19, 2026
    risk 0.59cvss 9.1epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to bypass security restrictions due to the exposure of intermediate certificate authority private keys in a publicly available update file.

  • CVE-2022-35643CriJul 29, 2022
    risk 0.59cvss 9.1epss 0.01

    IBM PowerVM VIOS 3.1 could allow a remote attacker to tamper with system configuration or cause a denial of service. IBM X-Force ID: 230956.

  • CVE-2026-16814HigAug 19, 2026
    risk 0.57cvss 8.8epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

  • CVE-2026-16686HigAug 19, 2026
    risk 0.53cvss 8.2epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to access NFS-exported filesystems due to improper authentication.

  • CVE-2026-15078HigAug 19, 2026
    risk 0.53cvss 8.1epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM could allow a remote attacker to gain unauthorized access to AIX systems due to improper validation of TLS certificates.

  • CVE-2026-15061HigAug 19, 2026
    risk 0.53cvss 8.2epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 's nimesis registration service could allow a remote attacker to overwrite files due to path traversal.

  • CVE-2026-16703HigAug 19, 2026
    risk 0.51cvss 7.8epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

  • CVE-2026-16819HigAug 19, 2026
    risk 0.50cvss 7.7epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-of-check time-of-use race condition.

  • CVE-2026-16818HigAug 19, 2026
    risk 0.49cvss 7.5epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.

  • CVE-2026-16817HigAug 19, 2026
    risk 0.49cvss 7.5epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

  • CVE-2026-16706HigAug 19, 2026
    risk 0.49cvss 7.5epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

  • CVE-2026-16690HigAug 19, 2026
    risk 0.49cvss 7.5epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.

  • CVE-2026-14970HigAug 19, 2026
    risk 0.49cvss 7.5epss

    IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 NIM server process is crashing during client registration due to buffer overflow.