CVE-2016-8972: High severity IBM AIX vulnerability
Published Feb 15, 2017
·Updated
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.
Affected Software
42 affected components
IBM AIX=6.1
IBM AIX=7.1
IBM AIX=7.2
IBM VIOS=2.2.0.0
IBM VIOS=2.2.0.10
IBM VIOS=2.2.0.11
IBM VIOS=2.2.0.12
IBM VIOS=2.2.0.13
IBM VIOS=2.2.1.0
IBM VIOS=2.2.1.1
IBM VIOS=2.2.1.3
IBM VIOS=2.2.1.4
IBM VIOS=2.2.1.5
IBM VIOS=2.2.1.6
IBM VIOS=2.2.1.7
IBM VIOS=2.2.1.8
IBM VIOS=2.2.2.0
IBM VIOS=2.2.2.1
IBM VIOS=2.2.2.2
IBM VIOS=2.2.2.3
IBM VIOS=2.2.2.4
IBM VIOS=2.2.2.6
IBM VIOS=2.2.2.70
IBM VIOS=2.2.3.0
IBM VIOS=2.2.3.1
IBM VIOS=2.2.3.2
IBM VIOS=2.2.3.3
IBM VIOS=2.2.3.4
IBM VIOS=2.2.3.50
IBM VIOS=2.2.3.51
IBM VIOS=2.2.3.52
IBM VIOS=2.2.3.60
IBM VIOS=2.2.3.70
IBM VIOS=2.2.3.80
IBM VIOS=2.2.4.0
IBM VIOS=2.2.4.10
IBM VIOS=2.2.4.21
IBM VIOS=2.2.4.22
IBM VIOS=2.2.4.23
IBM VIOS=2.2.4.30
IBM VIOS=2.2.5.0
IBM VIOS=2.2.5.10
Remediation
Event History
Feb 15, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionWeakness
Data Sourced
via NVD·07:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-8972?
CVE-2016-8972 is considered a high severity vulnerability as it allows a local user to gain root privileges.
2
How do I fix CVE-2016-8972?
To fix CVE-2016-8972, update your IBM AIX or IBM VIOS system to the latest security patches provided by IBM.
3
What versions are affected by CVE-2016-8972?
CVE-2016-8972 affects IBM AIX versions 6.1, 7.1, 7.2 and various versions of IBM VIOS.
4
Who is impacted by CVE-2016-8972?
Local users on systems running the affected versions of IBM AIX and VIOS are potentially impacted by CVE-2016-8972.
5
What does CVE-2016-8972 exploit?
CVE-2016-8972 exploits a vulnerability within the bellmail client allowing unauthorized root access.