CVE-1999-0094: Medium severity IBM AIX vulnerability
AIX piodmgrsu command allows local users to gain additional group privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX piodmgrsufrom your environment.Remove or disable the piodmgrsu command on affected AIX hosts if it is not required to prevent local users from gaining additional group privileges.
- Compensating control
If piodmgrsu cannot be removed immediately, restrict its execution to trusted administrative accounts (for example, remove execute permission for non-privileged users or apply filesystem ACLs), and enable monitoring/auditing of its use until a vendor patch or official remediation is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0094?
CVE-1999-0094 is considered a local privilege escalation vulnerability.
How do I fix CVE-1999-0094?
To fix CVE-1999-0094, apply the latest patches provided by IBM for the affected AIX versions.
Who is affected by CVE-1999-0094?
CVE-1999-0094 affects local users on IBM AIX versions 4.1.x and 4.2.
What does CVE-1999-0094 allow attackers to do?
CVE-1999-0094 allows local users to gain additional group privileges on affected AIX systems.
Is my system vulnerable to CVE-1999-0094?
You are vulnerable to CVE-1999-0094 if you are running the affected versions of IBM AIX without the necessary patches.