CVE-2012-4856: IBM Power 5

High severity, CVSS 7.9. EPSS: 1.2% chance of exploitation in the next 30 days.

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.

Affected products

  • IBM Power 5
  • IBM Power 5 System Firmware: up to and including sf240_418; version sf240_201_201 only; version sf240_202_201 only; version sf240_219_201 only; version sf240_222_201 only; version sf240_233_201 only; …

Published 2012-12-20. Last modified 2026-06-16.