QID 330160

Date Published: 2024-01-02

QID 330160: IBM AIX Multiple Vulnerabilities (python_advisory7)

Vulnerabilities in Python could allow a remote authenticated attacker to obtain sensitive information (CVE-2023-43804). AIX's Python packaging also includes Certifi, which is vulnerable to CVE-2023-37920.

Affected Version
AIX 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command : lslpp -L | grep -i python3.9.base;. The detection posts vulnerable if installed package version is less than patched version

Successful exploitation of the vulnerability may allow a remote authenticated attacker to obtain sensitive information

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    The vendor has released fixes to python_advisory7 this vulnerability.

    CVEs related to QID 330160

    Software Advisories
    Advisory ID Software Component Link
    python_advisory7 URL Logo aix.software.ibm.com/aix/efixes/security/python_advisory7.asc