CVE-2023-40371: IBM AIX information disclosure
IBM AIX 7.2, 7.3, VIOS 3.1's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls. IBM X-Force ID: 263476.
Other sources
IBM AIX's OpenSSH implementation could allow a non-privileged local user to access files outside of those allowed due to improper access controls.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2023-40371.
What is the severity of CVE-2023-40371?
The severity of CVE-2023-40371 is medium (6.2).
Which versions of IBM AIX and IBM VIOS are affected by CVE-2023-40371?
IBM AIX versions 7.2 and 7.3, as well as IBM VIOS version 3.1, are affected by CVE-2023-40371.
What is the impact of CVE-2023-40371?
CVE-2023-40371 allows a non-privileged local user to access files outside of those allowed due to improper access controls.
How can I fix the vulnerability in IBM AIX and IBM VIOS?
To fix the vulnerability in IBM AIX and IBM VIOS, it is recommended to apply the relevant patches provided by IBM.