QID 330109
Date Published: 2022-09-19
QID 330109: IBM Advanced Interactive eXecutive (AIX) Open Secure Sockets Layer (OpenSSL) Arbritary Code Execution Vulnerability (openssl_advisory36)
A vulnerability in OpenSSL could allow a remote attacker to execute arbitrary commands.OpenSSL is used by AIX as part of AIX's secure network communications
Affected Platform:
AIX 7.1, 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L | grep -i openssl.base. It also checks for interim fixes installed The detection posts vulnerable if installed package version is less than patched version and interim fixes are also not installed.
A vulnerability in OpenSSL could allow a remote attacker to execute arbitrary commands
Solution
The vendor has released fixes to openssl_advisory36 this vulnerability.
Vendor References
- openssl_advisory36 -
aix.software.ibm.com/aix/efixes/security/openssl_advisory36.asc
CVEs related to QID 330109
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| openssl_advisory36 |
|