CVE-2009-3516

IBM AIX 5.3.x-5.3.9 and 6.1.0-6.1.2 - Unauthenticated Access Restriction Bypass via NFSv4 Kerberos Credential Cache

Title source: llm
STIX 2.1

Description

gssd in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly handle the NFSv4 Kerberos credential cache, which allows local users to bypass intended access restrictions for Kerberized NFSv4 shares via unspecified vectors.

References (10)

Core 10
Core References
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/2788
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50496
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50444
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ50399
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49278
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6318
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49096
Vendor Advisory vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IZ49024
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/36545
Patch, Vendor Advisory x_refsource_confirm
http://aix.software.ibm.com/aix/efixes/security/nfs4_advisory.asc

Scores

EPSS 0.0037
EPSS Percentile 30.1%

Details

CWE
CWE-255
Status published
Products (7)
ibm/aix 5.3.0
ibm/aix 5.3.7
ibm/aix 5.3.8
ibm/aix 6.1
ibm/aix 6.1.0
ibm/aix 6.1.1
ibm/aix 6.1.2
Published Oct 01, 2009
Tracked Since Feb 18, 2026