CVE-2025-36236Path Traversal in IBM Vios

CWE-22Path Traversal3 documents3 sources
Severity
9.1CRITICALNVD
CNA8.2
EPSS
0.1%
top 81.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 13
Latest updateNov 14

Description

IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

CVEListV5ibm/vios3.1, 4.1+1
NVDibm/vios3.1.0, 4.1.0+1
CVEListV5ibm/aix7.2, 7.3+1
NVDibm/aix7.2, 7.3+1

🔴Vulnerability Details

2
GHSA
GHSA-5x48-f75w-m9hh: IBM AIX 72025-11-14
CVEList
AIX Path Traversal2025-11-13