QID 330124

Date Published: 2023-03-03

QID 330124: IBM AIX Multiple Vulnerabilities in Python (python_advisory)

AIX is affected by multiple vulnerabilities due to Python. Python is used by AIX as part of Ansible node management automation.

Affected Version
AIX 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i python3.9.base;. The detection posts vulnerable if installed package version is less than patched version

Successful exploitation of the vulnerabilities may lead to impacting confidentiality, integrity and availability

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    The vendor has released fixes to python_advisory this vulnerability.
    Software Advisories
    Advisory ID Software Component Link
    python_advisory URL Logo aix.software.ibm.com/aix/efixes/security/python_advisory.asc