7.8

CVE-2026-17171

Vulnerabilities in IBM AIX and PowerVM VIOS

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to overwrite arbitrary files due to improper resolution of symbolic links.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Vios Version >= 4.1.0 < 4.1.0.50
Ibm ≫ Vios Version >= 4.1.1.0 < 4.1.1.30
Ibm ≫ Vios Version >= 4.1.2.0 < 4.1.2.20
Ibm ≫ Aix Version >= 7.2.5 <= 7.2.5.212
Ibm ≫ Aix Version >= 7.3.2 <= 7.3.2.5
Ibm ≫ Aix Version >= 7.3.3 <= 7.3.3.2
Ibm ≫ Aix Version >= 7.3.4 <= 7.3.4.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
IBM 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://www.ibm.com/support/pages/node/7283858
Patch
Vendor Advisory