Description
The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.
References (9)
Core 9
Core References
Vendor Advisory x_refsource_confirm
http://aix.software.ibm.com/aix/efixes/security/tftp_advisory.asc
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/85366
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV42935
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV42934
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV40221
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV42932
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV42933
Third Party Advisory, VDB Entry vdb-entry
signature
x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19519
Vendor Advisory vendor-advisory
x_refsource_aixapar
http://www.ibm.com/support/docview.wss?uid=isg1IV42700
Scores
EPSS
0.0296
EPSS Percentile
85.8%
Details
CWE
CWE-264
Status
published
Products (3)
ibm/aix
6.1
ibm/aix
7.1
ibm/vios
2.2.2.2 fp-26_sp-02
Published
Jul 06, 2013
Tracked Since
Feb 18, 2026