New Search

AIX ftp vulnerability

oval:org.mitre.oval:def:19695

The FTP client in IBM AIX 6.1 and 7.1 and VIOS 2.2.1.4-FP-25 SP-02 does not properly manage privileges in an RBAC environment which allows attackers to bypass intended file-read restrictions by leveraging the setuid installation of the ftp executable file.

Family:
unix
Status:
ACCEPTED
Platform(s):
  • IBM AIX 7.1
  • IBM AIX 6.1
Class:
vulnerability
Reference(s):
  • CVE-2012-4845
Product(s):