CVE-2012-4856: IBM Power 5
High severity, CVSS 7.9. EPSS: 1.2% chance of exploitation in the next 30 days.
The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.
Affected products
- IBM Power 5
- IBM Power 5 System Firmware: up to and including sf240_418; version sf240_201_201 only; version sf240_202_201 only; version sf240_219_201 only; version sf240_222_201 only; version sf240_233_201 only; …
Published 2012-12-20. Last modified 2026-06-16.