Ibm Aix vulnerabilities

370 known vulnerabilities affecting ibm/aix.

Total CVEs
370
CISA KEV
0
Public exploits
68
Exploited in wild
0
Severity breakdown
CRITICAL47HIGH177MEDIUM119LOW26

Vulnerabilities

Page 1 of 19
CVE-2025-36250CRITICALCVSS 9.8v7.2v7.32025-11-13
CVE-2025-36250 [CRITICAL] CVE-2025-36250: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56346.
cvelistv5nvd
CVE-2025-36251CRITICALCVSS 9.8v7.2v7.32025-11-13
CVE-2025-36251 [CRITICAL] CVE-2025-36251: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a r IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to execute arbitrary commands due to improper process controls. This addresses additional attack vectors for a vulnerability that was previously addressed in CVE-2024-56347.
cvelistv5nvd
CVE-2025-36236CRITICALCVSS 9.1v7.2v7.32025-11-13
CVE-2025-36236 [HIGH] CWE-22 CVE-2025-36236: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (ni IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.
cvelistv5nvd
CVE-2025-36096HIGHCVSS 8.1v7.2v7.32025-11-13
CVE-2025-36096 [CRITICAL] CWE-522 CVE-2025-36096: IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in a IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which is susceptible to unauthorized access by an attacker using man in the middle techniques.
cvelistv5nvd
CVE-2025-36244MEDIUMCVSS 5.5v7.2v7.32025-09-16
CVE-2025-36244 [HIGH] CWE-454 CVE-2025-36244: IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, cou IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
cvelistv5nvd
CVE-2025-33112HIGHCVSS 8.4v7.3.3v7.32025-06-10
CVE-2025-33112 [HIGH] CWE-23 CVE-2025-33112: IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploi IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input.
cvelistv5nvd
CVE-2024-56347CRITICALCVSS 9.6v7.2v7.32025-03-18
CVE-2024-56347 [CRITICAL] CWE-114 CVE-2024-56347: IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to exe IBM AIX 7.2 and 7.3 nimsh service SSL/TLS protection mechanisms could allow a remote attacker to execute arbitrary commands due to improper process controls.
cvelistv5nvd
CVE-2024-56346CRITICALCVSS 10.0v7.2v7.32025-03-18
CVE-2024-56346 [CRITICAL] CWE-114 CVE-2024-56346: IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary co IBM AIX 7.2 and 7.3 nimesis NIM master service could allow a remote attacker to execute arbitrary commands due to improper process controls.
cvelistv5nvd
CVE-2024-47102MEDIUMCVSS 5.5v7.2v7.32024-12-25
CVE-2024-47102 [MEDIUM] CWE-863 CVE-2024-47102: IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerabil IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.
cvelistv5nvd
CVE-2024-52906MEDIUMCVSS 5.5v7.2v7.3+1 more2024-12-25
CVE-2024-52906 [MEDIUM] CWE-362 CVE-2024-52906: IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerab IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service.
cvelistv5nvd
CVE-2024-47115HIGHCVSS 7.8v7.2v7.3+1 more2024-12-07
CVE-2024-47115 [HIGH] CWE-78 CVE-2024-47115: IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the IBM AIX 7.2, 7.3 and VIOS 3.1 and 4.1 could allow a local user to execute arbitrary commands on the system due to improper neutralization of input.
cvelistv5nvd
CVE-2024-27260HIGHCVSS 8.4v7.2v7.3+1 more2024-05-16
CVE-2024-27260 [HIGH] CWE-250 CVE-2024-27260: IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulner IBM AIX could 7.2, 7.3, VIOS 3.1, and VIOS 4.1 allow a non-privileged local user to exploit a vulnerability in the invscout command to execute arbitrary commands. IBM X-Force ID: 283985.
cvelistv5nvd
CVE-2024-27273HIGHCVSS 7.8v7.2v7.3+1 more2024-05-07
CVE-2024-27273 [HIGH] CWE-266 CVE-2024-27273: IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could po IBM AIX's Unix domain (AIX 7.2, 7.3, VIOS 3.1, and VIOS 4.1) datagram socket implementation could potentially expose applications using Unix domain datagram sockets with SO_PEERID operation and may lead to privilege escalation. IBM X-Force ID: 284903.
cvelistv5nvd
CVE-2024-25021HIGHCVSS 8.4v7.3v7.3, VIOS 4.12024-02-22
CVE-2024-25021 [HIGH] CWE-114 CVE-2024-25021: IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vul IBM AIX 7.3, VIOS 4.1's Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary commands. IBM X-Force ID: 281320.
cvelistv5nvd
CVE-2023-45175MEDIUMCVSS 5.5v7.2v7.3+1 more2024-01-11
CVE-2023-45175 [MEDIUM] CWE-20 CVE-2023-45175: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the TCP/IP kernel extension to cause a denial of service. IBM X-Force ID: 267973.
cvelistv5nvd
CVE-2023-45171MEDIUMCVSS 5.5v7.2v7.3+1 more2024-01-11
CVE-2023-45171 [MEDIUM] CWE-20 CVE-2023-45171: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the kernel to cause a denial of service. IBM X-Force ID: 267969.
cvelistv5nvd
CVE-2023-45169MEDIUMCVSS 5.5v7.2v7.3+1 more2024-01-11
CVE-2023-45169 [MEDIUM] CWE-20 CVE-2023-45169: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the pmsvcs kernel extension to cause a denial of service. IBM X-Force ID: 267967.
cvelistv5nvd
CVE-2023-45173MEDIUMCVSS 5.5v7.2v7.3+1 more2024-01-11
CVE-2023-45173 [MEDIUM] CWE-20 CVE-2023-45173: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the NFS kernel extension to cause a denial of service. IBM X-Force ID: 267971.
cvelistv5nvd
CVE-2023-45165MEDIUMCVSS 5.5v7.2v7.3+1 more2023-12-22
CVE-2023-45165 [MEDIUM] CWE-20 CVE-2023-45165: IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SM IBM AIX 7.2 and 7.3 could allow a non-privileged local user to exploit a vulnerability in the AIX SMB client to cause a denial of service. IBM X-Force ID: 267963.
cvelistv5nvd
CVE-2023-45172MEDIUMCVSS 5.5v7.2v7.3+1 more2023-12-19
CVE-2023-45172 [MEDIUM] CWE-20 CVE-2023-45172: IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in IBM AIX 7.2, 7.3, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in AIX windows to cause a denial of service. IBM X-Force ID: 267970.
cvelistv5nvd
1 / 19Next →