Executive brief
IBM PowerVM NovaLink is a management tool used to scale and manage virtualization on IBM Power systems. A configuration issue in its programming interfaces (APIs) could allow a highly privileged user to perform unauthorized operations or access restricted data under specific non-default conditions. While the risk is low due to the high level of access required to exploit it, organizations should apply the provided updates to ensure the integrity of their virtualization management layer.
Technical details
A configuration vulnerability (CWE-16) exists in the IBM NovaLink APIs within PowerVM NovaLink versions 2.2.x and 2.3.x. The flaw is rooted in an API misconfiguration that, under non-default conditions, expands the attack surface. An attacker with high privileges and local access to the system could exploit this to perform unauthorized operations. The complexity of the attack is high, requiring specific environmental conditions to be met. IBM has released updates for the pvm-novalink package to remediate this issue.
Affected products
- IBM PowerVM Novalink 2.2.0, 2.2.1, 2.2.1.1, 2.3.0, 2.3.0.1, 2.3.1, 2.3.2
Timeline
- 2026-07-16: advisory: Initial publication by IBM
- 2026-07-17: disclosed: NVD publication date