CVE-1999-0092: High severity IBM AIX vulnerability

Published Oct 29, 1997
·
Updated

Various vulnerabilities in the AIX portmir command allows local users to obtain root access.

Affected Software

1 affected component
IBM AIX=4.2.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove IBM AIX portmir from your environment.

    Disable or uninstall the portmir command/binary on affected AIX systems if it is not required. Remove or rename the executable to prevent execution until an official patch or fix is available.

  2. Compensating control

    Restrict local user access on affected systems: disable interactive logins for non‑administrative accounts, remove unnecessary local accounts, and enforce least privilege for local users to reduce risk of local exploitation.

  3. Operational

    If exploitation is suspected, perform incident response: collect forensic evidence, audit logs for signs of local privilege escalation, rotate root and other high‑privilege credentials, and rebuild or reimage compromised hosts from trusted media.

Event History

Oct 29, 1997
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Feb 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-1999-0092?

CVE-1999-0092 is classified as a critical vulnerability due to the potential for local users to gain root access.

2

How do I fix CVE-1999-0092?

To fix CVE-1999-0092, you should apply the relevant patches provided by IBM for AIX version 4.2.1.

3

Who is affected by CVE-1999-0092?

Local users of IBM AIX version 4.2.1 are affected by CVE-1999-0092.

4

What are the consequences of exploiting CVE-1999-0092?

Exploiting CVE-1999-0092 could allow local users to gain unauthorized root access, leading to system compromise.

5

Is CVE-1999-0092 still a threat today?

While CVE-1999-0092 is an older vulnerability, it remains a threat if legacy systems running AIX 4.2.1 are still in use without mitigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203