SB2023062013 - Input validation error in IBM PowerVM Hypervisor



SB2023062013 - Input validation error in IBM PowerVM Hypervisor

Published: June 20, 2023

Security Bulletin ID SB2023062013
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Input validation error (CVE-ID: CVE-2023-30438)

The vulnerability allows a local user to obtain sensitive information or execute arbitrary code on the system.

The vulnerability exists due to insufficient validation of user-supplied input. A local user with access to a logical partition can perform an undetected violation of the isolation between logical partitions which could lead to data leakage or the execution of arbitrary code in other logical partitions on the same physical server.


Remediation

Install update from vendor's website.