Impact
IBM AIX and PowerVM VIOS contain an out‑of‑bounds read that can be triggered by a local attacker, allowing them to read memory beyond intended bounds and potentially expose sensitive data. The weakness is classified as CWE‑125, a classic information disclosure flaw.
Affected Systems
The vulnerability affects IBM AIX 7.2 and 7.3, as well as PowerVM VIOS 4.1. All releases prior to the service pack levels listed in the advisory are considered vulnerable: AIX SPs 7.3 TL04SP2, 7.3 TL03SP3, 7.3 TL02SP5, 7.2 TL05 SP13 and VIOS fix packs 4.1.2‑20, 4.1.1‑30, 4.1.0‑50. These security updates are cumulative and can be applied over any earlier affected level.
Risk and Exploitability
The CVSS score is 3.3, indicating a low severity risk. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker who can log in to the system or gain local access can exploit the out‑of‑bounds read to obtain confidential information. No public exploits are known, but the local nature of the flaw means privileged or local users can gain the capability to read protected memory.
OpenCVE Enrichment