CVSS2
Attack Vector
LOCAL
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:L/AC:M/Au:N/C:C/I:C/A:C
AI Score
Confidence
Low
EPSS
Percentile
5.1%
libodm.a in IBM AIX 6.1 and 7.1, and VIOS 2.2.x, allows local users to overwrite arbitrary files via a symlink attack on a temporary file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-2179.
Vendor | Product | Version | CPE |
---|---|---|---|
ibm | vios | 2.2.0.10 | cpe:2.3:a:ibm:vios:2.2.0.10:*:*:*:*:*:*:* |
ibm | vios | 2.2.0.11 | cpe:2.3:a:ibm:vios:2.2.0.11:*:*:*:*:*:*:* |
ibm | vios | 2.2.0.12 | cpe:2.3:a:ibm:vios:2.2.0.12:*:*:*:*:*:*:* |
ibm | vios | 2.2.0.13 | cpe:2.3:a:ibm:vios:2.2.0.13:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.0 | cpe:2.3:a:ibm:vios:2.2.1.0:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.1 | cpe:2.3:a:ibm:vios:2.2.1.1:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.3 | cpe:2.3:a:ibm:vios:2.2.1.3:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.4 | cpe:2.3:a:ibm:vios:2.2.1.4:*:*:*:*:*:*:* |
ibm | vios | 2.2.1.4 | cpe:2.3:a:ibm:vios:2.2.1.4:fp-25_sp-02:*:*:*:*:*:* |
ibm | vios | 2.2.1.8 | cpe:2.3:a:ibm:vios:2.2.1.8:*:*:*:*:*:*:* |
aix.software.ibm.com/aix/efixes/security/libodm_advisory.asc
packetstormsecurity.com/files/127067/IBM-AIX-6.1.8-Privilege-Escalation.html
www.exploit-db.com/exploits/33725
www.ibm.com/support/docview.wss?uid=isg1IV60299
www.ibm.com/support/docview.wss?uid=isg1IV60303
www.ibm.com/support/docview.wss?uid=isg1IV60311
www.ibm.com/support/docview.wss?uid=isg1IV60312
www.ibm.com/support/docview.wss?uid=isg1IV60313
www.ibm.com/support/docview.wss?uid=isg1IV60314
www.securitytracker.com/id/1030401
exchange.xforce.ibmcloud.com/vulnerabilities/93595
www.portcullis-security.com/security-research-and-downloads/security-advisories/cve-2014-3977/