Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Pavel Jirout

Researcher fromNovartis
#39600of 53,633
6.9Total CVSS
Vulnerabilities · 1
PT-2015-2331
6.9
2015-10-12
Ibm · Aix · CVE-2015-4948
**Name of the Vulnerable Software and Affected Versions** IBM AIX versions 5.3, 6.1, and 7.1 VIOS version 2.2.x **Description** The issue is related to the netstat component in the AIX operating system, which has inadequate access restrictions to certain functions. This allows a local attacker to potentially gain elevated privileges. The vulnerability can be exploited when a fibre channel adapter is used. **Recommendations** For IBM AIX versions 5.3, 6.1, and 7.1, consider restricting access to the netstat component until a fix is available. For VIOS version 2.2.x, restrict the use of the netstat function when a fibre channel adapter is present to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.