QID 330125
Date Published: 2023-03-03
QID 330125: IBM AIX Multiple Vulnerabilities in Python (python_advisory2)
Vulnerabilities in Python could allow an attacker to execute arbitrary code (CVE-2022-40674) or cause a denial of service (CVE-2020-10735). Python is used by AIX as part of Ansible node management automation.
Affected Version
AIX 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i python3.9.base;. The detection posts vulnerable if installed package version is less than patched version
Successful exploitation of the vulnerabilities may lead to impacting confidentiality, integrity and availability
Solution
The vendor has released fixes to python_advisory2 this vulnerability.
Vendor References
- python_advisory2 -
aix.software.ibm.com/aix/efixes/security/python_advisory2.asc
CVEs related to QID 330125
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| python_advisory2 |
|