PT-2025-46921 · Ibm · Aix +2
Published
2025-11-13
·
Updated
2025-11-28
·
CVE-2025-36096
CVSS v3.1
9.0
9.0
Critical
| Base vector | Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM AIX versions 7.2 and 7.3
IBM VIOS versions 3.1 and 4.1
Description
The software stores NIM private keys used in NIM environments in an insecure manner, making them susceptible to unauthorized access by an attacker employing man-in-the-middle techniques. The NIM server, previously known as the NIM master service (nimesis), may allow a remote attacker to traverse directories and write arbitrary files on the system by sending a specially crafted URL request.
Recommendations
IBM AIX version 7.2: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IBM AIX version 7.3: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IBM VIOS version 3.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
IBM VIOS version 4.1: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
dbugs@ptsecurity.com
Weakness Enumeration
Related Identifiers
CVE-2025-36096
Affected Products
Aix
Ibm Aix
Vios
References · 19
- https://ibm.com/support/pages/node/7251173 · Patch, Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-36096 · Security Note
- https://t.me/poxek/5676 · Telegram Post
- https://twitter.com/zoomeye_team/status/1990263006878654758 · Twitter Post
- https://t.me/cveNotify/142742 · Telegram Post
- https://reddit.com/r/CVEWatch/comments/1p14p4v/top_10_trending_cves_19112025 · Reddit Post
- https://twitter.com/offseq/status/1989144065540047278 · Twitter Post
- https://twitter.com/0dayPublishing/status/1989357644516032934 · Twitter Post
- https://twitter.com/CCBalert/status/1989358706564210894 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1ozdgd3/top_10_trending_cves_17112025 · Reddit Post
- https://twitter.com/transilienceai/status/1994247716642455999 · Twitter Post
- https://twitter.com/gothburz/status/1989535908236800218 · Twitter Post
- https://twitter.com/guriguri_dW/status/1991334314018210273 · Twitter Post
- https://reddit.com/r/CVEWatch/comments/1p092hc/top_10_trending_cves_18112025 · Reddit Post
- https://twitter.com/autumn_good_35/status/1989376182429856000 · Twitter Post