First published: Sun Nov 08 2015(Updated: )
CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Powerha System Mirror | ||
IBM AIX | =6.1 | |
IBM AIX | =7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5005 has a moderate severity rating due to the potential for unauthorized privilege escalation in IBM PowerHA SystemMirror.
To fix CVE-2015-5005, apply the security updates provided in IBM's advisories for PowerHA SystemMirror.
CVE-2015-5005 affects remote authenticated users of IBM PowerHA SystemMirror on AIX versions 6.1 and 7.1.
CVE-2015-5005 exploits the presence on the cluster-wide password-change list to perform an 'su root' action.
CVE-2015-5005 is considered a remote vulnerability since it can be exploited by remote authenticated users.