Impact
IBM AIX 7.2, 7.3 and IBM PowerVM VIOS 4.1 contain a flaw that allows a local attacker to hijack the ODMDIR environment variable and execute arbitrary commands on the host. This vulnerability was identified as an improper validation error that enables code execution with the privileges of the affected process, potentially leading to full system compromise if the attacker has local access. The weakness falls under CWE-78: Improper Neutralization of Special Elements used in a Command Construction.
Affected Systems
The affected systems are IBM AIX releases 7.2 and 7.3, including all sub‑levels of the 7.2 and 7.3 technical layers, and IBM PowerVM VIOS 4.1 (all 4.1.x variants). Fixes are provided as IBM AIX Service Packs and PowerVM VIOS Fix Packs: AIX SP2, SP3, SP5 and SP13 (cumulative) and VIOS 4.1.0.50, 4.1.1.30 and 4.1.2.20 (cumulative). Each SP/FP contains the remediation for this vulnerability and all preceding fixes.
Risk and Exploitability
The CVSS base score of 8.8 classifies the issue as high severity, reflecting the threat of local command execution. The EPSS score is not available, so the exploitation probability cannot be quantified from current data. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring the attacker to be able to run commands on the affected host; no remote exploitation path is documented.
OpenCVE Enrichment