CVE-2025-36236: AIX Path Traversal
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36236?
CVE-2025-36236 has a critical severity rating due to the potential for remote attackers to traverse directories and write arbitrary files on affected systems.
How do I fix CVE-2025-36236?
To fix CVE-2025-36236, update IBM AIX or IBM VIOS to the latest versions provided by IBM that include patches for this vulnerability.
Which IBM products are affected by CVE-2025-36236?
CVE-2025-36236 affects IBM AIX versions 7.2 and 7.3, as well as IBM VIOS versions 3.1 and 4.1.
What type of attack can exploit CVE-2025-36236?
CVE-2025-36236 can be exploited through specially crafted URL requests allowing attackers to perform directory traversal attacks.
Is there a workaround for CVE-2025-36236?
There are no official workarounds for CVE-2025-36236; applying security updates is the recommended approach to mitigate the risk.