CVE-1999-0338: High severity IBM AIX vulnerability
AIX Licensed Program Product performance tools allow local users to gain root access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
IBM AIX Licensed Program Product: performance toolsfrom your environment.Uninstall or disable the AIX performance tools component if it is not required on the system.
- Configuration
Restrict executable permissions of the performance tool binaries so only root can execute them (e.g., adjust ownership and mode with chown/chmod) to prevent local non-privileged users from running the tools.
IBM AIX performance tools execute permission = root-only - Compensating control
Restrict local user access to affected hosts until a vendor fix is available: remove or disable unneeded local accounts, restrict shell/login access via PAM or access control lists, and isolate vulnerable systems from untrusted users/networks.
- Operational
Treat systems as potentially compromised: audit logs for unauthorized root activity, rotate administrative/root credentials and keys, and rebuild or restore affected systems from known-good backups if compromise is confirmed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0338?
CVE-1999-0338 is classified as a local privilege escalation vulnerability, allowing unprivileged users to gain root access.
How do I fix CVE-1999-0338?
To fix CVE-1999-0338, you should update your AIX system to a version where this vulnerability is patched.
Which versions of AIX are affected by CVE-1999-0338?
CVE-1999-0338 affects AIX versions 3.2.4 and 3.2.5.
What are the potential risks of CVE-1999-0338?
The potential risks of CVE-1999-0338 include unauthorized users gaining root access, leading to system compromise.
Is CVE-1999-0338 active in the wild?
There is no current evidence indicating that CVE-1999-0338 is actively exploited in the wild, but systems should be patched to prevent potential exploitation.