QID 330095
Date Published: 2022-03-09
QID 330095: IBM Advanced Interactive eXecutive (AIX) File Creation Vulnerability (audit commands)
There are vulnerabilities in bos.rte.filesystem that affect AIX.
IBM AIX could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands.
Affected Platform:
AIX 7.1,7.2,7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : - "lslpp -L". It also checks for interim fixes installed using the command "emgr -c" or "instfix -k". The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.
A successful exploitation could allow a local user with elevated privileges to cause a denial of service due to a file creation vulnerability in the audit commands.
Solution
The vendor has released fixes to resolve this vulnerability.
Vendor References
- CVE-2021-38955 -
aix.software.ibm.com/aix/efixes/security/audit_advisory.asc
CVEs related to QID 330095
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| audit_advisory |
|