Executive brief
IBM PowerVM Novalink, a tool used to manage virtualization on IBM Power Systems, is vulnerable to a denial of service attack. By sending a specially crafted request, a remote attacker can force the server to consume excessive memory. This can lead to system instability or a complete service outage, preventing administrators from managing their virtualized environment.
Technical details
IBM PowerVM Novalink is affected by a denial of service vulnerability (CWE-400) originating from its use of IBM WebSphere Application Server Liberty. The flaw allows a remote, unauthenticated attacker to send a specially crafted HTTP request that triggers uncontrolled resource consumption. Specifically, the exploit causes the server to exhaust available memory resources, leading to a denial of service condition. The vulnerability is reachable over the network without user interaction. IBM has released patches for affected versions 2.2.x and 2.3.x to mitigate this issue.
Affected products
- IBM PowerVM Novalink 2.2.0, 2.2.1, 2.2.1.1, 2.3.0, 2.3.0.1, 2.3.1, 2.3.2
Timeline
- 2026-07-16: advisory: Initial publication by IBM
- 2026-07-17: disclosed: NVD publication date