Impact
IBM PowerVM Novalink APIs were misconfigured in versions 2.2.02.2.12.2.1.1 and 2.3.02.3.0.12.3.12.3.2, expanding the attack surface and allowing unintended or unauthorized operations when non‑default settings are in use. This misconfiguration can permit an attacker to invoke API calls that would normally be restricted, potentially leading to privileged actions or disruption of the virtualization environment.
Affected Systems
IBM PowerVM Novalink, specifically the 2.2.02.2.12.2.1.1 and 2.3.02.3.0.12.3.12.3.2 versions, are impacted. These are identified by the CNA vendor/product entry IBM:PowerVM Novalink and the corresponding CPE strings for the two affected releases.
Risk and Exploitability
The CVSS score of 3.9 places this vulnerability in the low‑severity range. The EPSS score of less than 1% indicates a very low probability of exploitation at this time. It is not listed in CISA’s KEV catalog. The likely attack vector is via the Novalink APIs, potentially remote if those APIs are exposed beyond the internal network. Exploitation would require the attacker to reach the APIs in a configuration that is not the default and perform an operation that is normally restricted.
OpenCVE Enrichment