CVE-2011-1384
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a…
Does this matter?
Lower severity and a low EPSS score (0.33%). Track it; it rarely justifies an emergency change on its own.
Description
The (1) bin/invscoutClient_VPD_Survey and (2) sbin/invscout_lsvpd programs in invscout.rte before 2.2.0.19 on IBM AIX 7.1, 6.1, 5.3, and earlier allow local users to delete arbitrary files, or trigger inventory scout operations on arbitrary files, via a symlink attack on an unspecified file.
- CVSS 2.0
- 4.0 MEDIUMAV:L/AC:H/Au:N/C:N/I:C/A:N
- EPSS
- 0.33% probability · 26th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- ibm/invscout.rte
- Source
- cve@mitre.org
References
- http://aix.software.ibm.com/aix/efixes/security/invscout_advisory2.ascVendor Advisory
- http://secunia.com/advisories/47222Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IV11643
- http://www.securityfocus.com/bid/51059
- http://www.securityfocus.com/bid/51083
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71615
- http://aix.software.ibm.com/aix/efixes/security/invscout_advisory2.ascVendor Advisory
- http://secunia.com/advisories/47222Vendor Advisory
- http://www-01.ibm.com/support/docview.wss?uid=isg1IV11643
- http://www.securityfocus.com/bid/51059
- http://www.securityfocus.com/bid/51083
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71615
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.