CVE-2014-8904: High severity ibm virtual i/o server (vios) vulnerability
Published Jan 15, 2015
·Updated
lquerylv in cmdlvm in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x allows local users to gain privileges via a crafted DBGCMDLQUERYLV environment-variable value.
Affected Software
27 affected components
IBM VIOS=2.2.0.10
IBM VIOS=2.2.0.11
IBM VIOS=2.2.0.12
IBM VIOS=2.2.0.13
IBM VIOS=2.2.1.0
IBM VIOS=2.2.1.1
IBM VIOS=2.2.1.3
IBM VIOS=2.2.1.4
IBM VIOS=2.2.1.5
IBM VIOS=2.2.1.6
IBM VIOS=2.2.1.7
IBM VIOS=2.2.1.8
IBM VIOS=2.2.1.9
IBM VIOS=2.2.2.0
IBM VIOS=2.2.2.1
IBM VIOS=2.2.2.2
IBM VIOS=2.2.2.3
IBM VIOS=2.2.2.4
IBM VIOS=2.2.2.5
IBM VIOS=2.2.3.0
IBM VIOS=2.2.3.1
IBM VIOS=2.2.3.2
IBM VIOS=2.2.3.3
IBM VIOS=2.2.3.4
IBM AIX=5.3
IBM AIX=6.1
IBM AIX=7.1
Event History
Jan 15, 2015
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-8904?
CVE-2014-8904 has a medium severity rating due to the potential for local privilege escalation.
2
How do I fix CVE-2014-8904?
To fix CVE-2014-8904, apply the recommended patches provided by IBM for your specific version of AIX or VIOS.
3
Which versions of IBM AIX and VIOS are affected by CVE-2014-8904?
CVE-2014-8904 affects IBM AIX versions 5.3, 6.1, and 7.1, as well as several versions of IBM VIOS.
4
Can CVE-2014-8904 be exploited remotely?
CVE-2014-8904 cannot be exploited remotely as it requires local access to the system.
5
What is the impact of exploiting CVE-2014-8904?
Exploiting CVE-2014-8904 allows local users to gain elevated privileges, potentially compromising the system's integrity.