CVE-2023-30438: IBM Powervm Hypervisor
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An internally discovered vulnerability in PowerVM on IBM Power9 and Power10 systems could allow an attacker with privileged user access to a logical partition to perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server. IBM X-Force ID: 252706.
Affected products
- IBM Powervm Hypervisor: from fw950, before fw950.71 (fixed in fw950.71); from fw1010.00, before fw1010.51 (fixed in fw1010.51); from fw1030.00, before fw1030.11 (fixed in fw1030.11); from fw1020.00, before fw1020.31 (fixed in fw1020.31)
Published 2023-05-17. Last modified 2026-06-17.