QID 330134

Date Published: 2023-04-26

QID 330134: IBM AIX Inventory Scout Arbitrary Command Execution Vulnerability (invscout_advisory4)

A vulnerability in the AIX invscout command could allow a non-privileged local user to obtain root privileges

Affected Versions:-
AIX 7.1,7.2 and 7.3 running invscout.rte versions prior to 2.2.0.24.

QID Detection logic
It checks for the vulnerable file of invscout.rte using command lslpp -L | grep -i invscout.rte Prerequisite- For AIX 7.1 and 7.2 you must be on the 'bos.rte.libc prereq' level before installing the new invscout.rte package.

Successful exploit may allow a non-privileged local user to execute arbitrary commands

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Vendor fixes are available to resolve the issue. Refer to AIX invscout advisory 4 to address this issue and obtain details on the fixes.

    CVEs related to QID 330134

    Software Advisories
    Advisory ID Software Component Link
    invscout_advisory4.asc URL Logo aix.software.ibm.com/aix/efixes/security/invscout_advisory4.asc