CVE-2012-0745IBM Vios vulnerability

CWE-2643 documents3 sources
Severity
7.2HIGHNVD
EPSS
0.1%
top 75.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 4
Latest updateMay 17

Description

The getpwnam function in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.1.0.10 through 2.2.1.3 does not properly interact with customer-extended LDAP user filtering, which allows local users to gain privileges via unspecified vectors.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

NVDibm/vios11 versions+10
NVDibm/aix5.3, 6.1, 7.1+2

🔴Vulnerability Details

2
GHSA
GHSA-89cr-c8v5-9r95: The getpwnam function in IBM AIX 52022-05-17
CVEList
CVE-2012-0745: The getpwnam function in IBM AIX 52012-05-04
CVE-2012-0745 — IBM Vios vulnerability | cvebase