Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2014-8904IBM Vios vulnerability

CWE-2644 documents4 sources
Severity
7.2HIGHNVD
EPSS
0.6%
top 31.71%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 15
Latest updateMay 13

Description

lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMD_LQUERYLV environment-variable value.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages2 packages

NVDibm/vios24 versions+23
NVDibm/aix5.3, 6.1, 7.1+2

🔴Vulnerability Details

2
GHSA
GHSA-jcxw-wc96-m6qp: lquerylv in cmdlvm in IBM AIX 52022-05-13
CVEList
CVE-2014-8904: lquerylv in cmdlvm in IBM AIX 52015-01-15

💥Exploits & PoCs

1
Exploit-DB
AIX 7.1 - 'lquerylv' Local Privilege Escalation2015-10-30
CVE-2014-8904 — IBM Vios vulnerability | cvebase