IBM AIX Luns Ownership Security Bypass Vulnerability
BID:48219
Info
IBM AIX Luns Ownership Security Bypass Vulnerability
| Bugtraq ID: | 48219 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 11 2011 12:00AM |
| Updated: | Jun 11 2011 12:00AM |
| Credit: | IBM |
| Vulnerable: |
IBM Aix 5300-12 IBM Aix 5300-11 IBM Aix 5300-10 |
| Not Vulnerable: | |
Discussion
IBM AIX Luns Ownership Security Bypass Vulnerability
IBM AIX is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and change luns ownership.
IBM AIX is prone to a security-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions and change luns ownership.
Exploit / POC
IBM AIX Luns Ownership Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
IBM AIX Luns Ownership Security Bypass Vulnerability
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
IBM AIX Luns Ownership Security Bypass Vulnerability
References:
References:
- AIX Homepage (IBM)
- Fix pack information for: Luns change ownership when mpio_get_config is run. (IBM)
- IZ82968: LUNS CHANGE OWNERSHIP WHEN MPIO_GET_CONFIG IS RUN. APPLIES TO AIX 5300- (IBM)
- IZ86230: LUNS CHANGE OWNERSHIP WHEN MPIO_GET_CONFIG IS RUN. APPLIES TO AIX 5300- (IBM)
- IZ86569: LUNS CHANGE OWNERSHIP WHEN MPIO_GET_CONFIG IS RUN. APPLIES TO AIX 5300- (IBM)