QID 330145
Date Published: 2023-08-22
QID 330145: IBM AIX Security Restrictions Bypass due to Python (python_advisory5)
A vulnerability in Python could allow a remote attacker to bypass security restrictions (CVE-2023-24329). Python is used by AIX as part of Ansible node management automation.
Affected Version
AIX 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i python3.9.base;. The detection posts vulnerable if installed package version is less than patched version
Successful exploitation of the vulnerability may allow remote attacker to bypass security restrictions
Solution
The vendor has released fixes to python_advisory5 this vulnerability.
Vendor References
- python_advisory5 -
aix.software.ibm.com/aix/efixes/security/python_advisory5.asc
CVEs related to QID 330145
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| python_advisory5 |
|