CVE-2024-56477: IBM Power Hardware Management Console

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

IBM Power Hardware Management Console V10.3.1050.0 could allow an authenticated user to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.

Affected products

  • IBM Power Hardware Management Console: version 10.3.1060.0 only

Published 2025-02-14. Last modified 2026-06-17.