CVE-1999-1119: Critical severity IBM AIX vulnerability
FTP installation script anon.ftp in AIX insecurely configures anonymous FTP, which allows remote attackers to execute arbitrary commands.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
AIX/anon.ftpfrom your environment.Remove, rename, or do not install the anon.ftp installation script. Uninstall or revert any components or configuration changes introduced by anon.ftp to eliminate the insecure anonymous FTP configuration.
- Configuration
Disable anonymous FTP by configuring the FTP server to disallow anonymous logins and avoid running the anon.ftp installation script. Update the FTP configuration to remove or block the 'anonymous' user account and any mappings created by anon.ftp.
AIX FTP (anon.ftp installation script) anonymous FTP = disabled - Compensating control
Until the insecure configuration is removed or fixed, restrict access to the FTP service to trusted IPs using firewall rules, network ACLs, or segmentation, and block anonymous FTP access at the network perimeter.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1119?
CVE-1999-1119 is considered a high severity vulnerability due to its potential to allow remote attackers to execute arbitrary commands.
How do I fix CVE-1999-1119?
To fix CVE-1999-1119, reconfigure the anonymous FTP settings to restrict access and limit the commands that can be executed.
Who is affected by CVE-1999-1119?
CVE-1999-1119 affects users of IBM AIX who have installed the insecure anonymous FTP configuration.
What type of vulnerability is CVE-1999-1119?
CVE-1999-1119 is an arbitrary command execution vulnerability resulting from improper configuration of the FTP service.
What should I do if I cannot patch CVE-1999-1119 immediately?
If immediate patching is not possible for CVE-1999-1119, consider disabling anonymous FTP access until a fix can be applied.