QID 330137
Date Published: 2023-05-08
QID 330137: IBM AIX Vulnerability in perl (perl_advisory6)
AIX is vulnerable to HTTP request smuggling due to Perl
A vulnerability in libwww-perl could allow an attacker to poison web caches, bypass web application firewall protection, and conduct XSS attacks (CVE-2022-31081)
Affected Platform:
AIX 7.1, 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L | grep -i per.rte. The detection posts vulnerable if installed package version is less than patched version
Successful exploitation may impact the confidentiality, integrity and availability
Solution
The vendor has released fixed versions under perl_advisory6
Vendor References
- perl_advisory6 -
aix.software.ibm.com/aix/efixes/security/perl_advisory6.asc
CVEs related to QID 330137
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| perl_advisory6 |
|