CVE-2014-0899IBM AIX vulnerability

CWE-2643 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
0.3%
top 46.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11
Latest updateMay 17

Description

ftpd in IBM AIX 7.1.1 before SP10 and 7.1.2 before SP5, when a Workload Partition (aka WPAR) for AIX 5.2 or 5.3 is used, allows remote authenticated users to bypass intended permission settings and modify arbitrary files via FTP commands.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDibm/aix7.1.1, 7.1.2+1

🔴Vulnerability Details

2
GHSA
GHSA-p6cv-q8p6-3vx5: ftpd in IBM AIX 72022-05-17
CVEList
CVE-2014-0899: ftpd in IBM AIX 72014-03-11
CVE-2014-0899 — IBM AIX vulnerability | cvebase