QID 330112
Date Published: 2022-10-17
QID 330112: IBM AIX Inventory Scout Privilege Escalation Vulnerability
A vulnerability in the AIX invscout command could allow a non-privileged local user to obtain root privileges
Affected Versions:-
AIX 7.1,7.2 and 7.3 running invscout.rte versions prior to 2.2.0.22.
QID Detection logic
It checks for the vulnerable file of invscout.rte using command lslpp -L | grep -i invscout.rte
Prerequisite- For AIX 7.1 and 7.2 you must be on the 'bos.rte.libc prereq' level before installing the new invscout.rte package.
successful exploit may lead to privilege escalation impacting the confidentiality, integrity and availability of data.
Solution
Vendor fixes are available to resolve the issue. Refer to AIX invscout advisory to address this issue and obtain details on the fixes.
Vendor References
- invscout_advisory3 -
aix.software.ibm.com/aix/efixes/security/invscout_advisory3.asc
CVEs related to QID 330112
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| invscout_advisory3 |
|