QID 330083
Date Published: 2021-06-28
QID 330083: IBM AIX Vulnerabilities in power9 (power9_advisory)
There are vulnerabilities in perl.rte that affect AIX.
Affected Platform:
AIX 7.1,7.2
Note: The detection requires root privileges to run "emgr -c" to check for patches. In absence of such privileges, the detection may not output actual results.
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : - "lslpp -L". It also checks for interim fixes installed using the command "emgr -c" or "instfix -k". The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.
On successful exploitation, IBM Power9 processors could allow a local user to obtain sensitive information.
Solution
The vendor has released fixes to resolve this vulnerability.
Vendor References
- power9_advisory -
aix.software.ibm.com/aix/efixes/security/power9_advisory.asc
CVEs related to QID 330083
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| power9_advisory |
|