QID 330165

Date Published: 2024-02-23

QID 330165: IBM AIX Arbitrary Command Execution Vulnerability in perl (perl_advisory8)

AIX is vulnerable to execution of arbitrary commands (CVE-2024-25021, CVE-2023-47038, CVE-2023-47100)

Affected Platform:
AIX 7.3
QID Detection Logic (Authenticated):
The detection checks for installed packages version via command lslpp -L | grep -i perl.rte. The detection posts vulnerable if installed package version is less than patched version

Successful exploitation may impact the confidentiality, integrity

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    The vendor has released fixed versions under perl_advisory8

    CVEs related to QID 330165

    Software Advisories
    Advisory ID Software Component Link
    perl_advisory8 URL Logo aix.software.ibm.com/aix/efixes/security/perl_advisory8.asc