QID 330151

Date Published: 2023-10-12

QID 330151: IBM AIX Vulnerability in perl (perl_advisory7)

AIX is vulnerable to sensitive information exposure due to Perl (CVE-2023-31484 and CVE-2023-31486)

Affected Platform:
AIX 7.2, 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L | grep -i per.rte. The detection posts vulnerable if installed package version is less than patched version

Successful exploitation may impact the confidentiality, integrity

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as High - 6.4 severity.
  • Solution
    The vendor has released fixed versions under perl_advisory7

    CVEs related to QID 330151

    Software Advisories
    Advisory ID Software Component Link
    perl_advisory7 URL Logo aix.software.ibm.com/aix/efixes/security/perl_advisory7.asc