Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-17693 | IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input. |
Solution
IBM strongly recommends addressing the vulnerability now. The AIX and VIOS fixes can be downloaded via https from: https://aix.software.ibm.com/aix/efixes/security/perl_fix9.tar
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://www.ibm.com/support/pages/node/7236103 |
|
Fri, 25 Jul 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:ibm:aix:7.3:*:*:*:*:*:*:* |
cpe:2.3:o:ibm:aix:7.3.3:*:*:*:*:*:*:* |
Fri, 25 Jul 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:7.3:*:*:*:*:*:*:* |
Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 10 Jun 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IBM AIX 7.3 and IBM VIOS 4.1.1 Perl implementation could allow a non-privileged local user to exploit a vulnerability to execute arbitrary code due to improper neutralization of pathname input. | |
| Title | IBM AIX command execution | |
| First Time appeared |
Ibm
Ibm aix Ibm vios |
|
| Weaknesses | CWE-23 | |
| CPEs | cpe:2.3:a:ibm:vios:4.1.1:*:*:*:*:*:*:* cpe:2.3:o:ibm:aix:7.2:*:*:*:*:*:*:* |
|
| Vendors & Products |
Ibm
Ibm aix Ibm vios |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: ibm
Published:
Updated: 2025-08-24T11:57:38.663Z
Reserved: 2025-04-15T17:50:49.744Z
Link: CVE-2025-33112
Updated: 2025-06-10T17:52:23.073Z
Status : Analyzed
Published: 2025-06-10T17:23:11.607
Modified: 2025-07-25T19:09:10.797
Link: CVE-2025-33112
No data.
OpenCVE Enrichment
No data.
EUVD