Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain a path traversal flaw (CWE‑22) that could allow an unauthenticated remote user to read arbitrary files on the system. If exploited, the attacker could obtain confidential data or configuration files that reveal privileged information, potentially jumping from a non‑privileged footprint to higher‑level access through the knowledge gleaned.
Affected Systems
The vulnerability affects all IBM AIX installations running versions 7.2 and 7.3 prior to the service packs listed in the advisory (SP2 for AIX 7.3 TL04, SP3 for AIX 7.3 TL03, SP5 for AIX 7.3 TL02 and SP13 for AIX 7.2 TL05). IBM PowerVM VIOS 4.1 is impacted for all releases up to and including 4.1, with remedial fix packs 4.1.2.20, 4.1.1.30 and 4.1.0.50 required to address the issue.
Risk and Exploitability
The CVSS score of 3.7 signifies moderate severity, and while the EPSS score is not provided, the lack of a KEV listing suggests no widely known active exploitation. The defect can be leveraged remotely, likely by sending a crafted request to a vulnerable service that interprets file paths incorrectly. No user interaction is required beyond establishing network connectivity to the target. Given the potential for disclosing sensitive information, the patching recommendation is urgent.
OpenCVE Enrichment