CVE-1999-0086: Medium severity IBM AIX vulnerability
AIX routed allows remote users to modify sensitive files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX routedfrom your environment.Uninstall or remove the routed daemon from systems where it is not required.
- Configuration
Disable the routed daemon/service on affected AIX systems if it is not required: stop the service and prevent it from starting at boot.
IBM AIX routed service_enabled = false - Compensating control
Restrict network access to the routed service using host-based firewalls, network ACLs, or perimeter firewalls so only trusted management IPs can reach the service.
- Operational
Audit sensitive system files for unauthorized modifications, restore affected files from known-good backups as needed, and rotate any credentials or keys that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0086?
CVE-1999-0086 is considered a critical vulnerability as it allows remote users to modify sensitive files.
How do I fix CVE-1999-0086?
Fix CVE-1999-0086 by applying the latest security patches provided by IBM for the affected AIX versions.
What versions of AIX are affected by CVE-1999-0086?
CVE-1999-0086 affects AIX versions 3.2, 4.1, 4.2, and 4.3.
Can CVE-1999-0086 be exploited remotely?
Yes, CVE-1999-0086 can be exploited remotely by malicious users.
What type of files can be modified due to CVE-1999-0086?
CVE-1999-0086 allows modification of sensitive system files which could potentially compromise system integrity.