QID 330113

Date Published: 2023-02-20

QID 330113: IBM AIX Multiple Vulnerabilities due to RPM (rpm_advisory)

AIX is vulnerable to arbitrary code execution (CVE-2021-20271), RPM database corruption (CVE-2021-3421), and denial of service (CVE-2021-20266) due to RPM. RPM is used by AIX for package management.

Affected Versions:
AIX 7.1, 7.2,7.3

QID Detection logic:
This QID checks for the vulnerable versions of AIX.

A successful exploit could lead to denial of service, arbritrary code execution and rpm database corruption.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as Medium - 5.1 severity.
  • Solution
    The vendor has released fixes to resolve this vulnerability. Refer to AIX rpm_advisory to obtain more information.

    CVEs related to QID 330113

    Software Advisories
    Advisory ID Software Component Link
    rpm_advisory URL Logo aix.software.ibm.com/aix/efixes/security/rpm_advisory.asc