CVE-2015-5005: High severity ibm powerha systemmirror vulnerability
Published Nov 8, 2015
·Updated
CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.
Affected Software
3 affected components
IBM Powerha System Mirror
IBM AIX=6.1
IBM AIX=7.1
Event History
Nov 8, 2015
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-5005?
CVE-2015-5005 has a moderate severity rating due to the potential for unauthorized privilege escalation in IBM PowerHA SystemMirror.
2
How do I fix CVE-2015-5005?
To fix CVE-2015-5005, apply the security updates provided in IBM's advisories for PowerHA SystemMirror.
3
Who is affected by CVE-2015-5005?
CVE-2015-5005 affects remote authenticated users of IBM PowerHA SystemMirror on AIX versions 6.1 and 7.1.
4
What does CVE-2015-5005 exploit?
CVE-2015-5005 exploits the presence on the cluster-wide password-change list to perform an 'su root' action.
5
Is CVE-2015-5005 a local or remote vulnerability?
CVE-2015-5005 is considered a remote vulnerability since it can be exploited by remote authenticated users.