CVE-2015-5005

IBM PowerHA SystemMirror - Authenticated Privilege Escalation via CSPOC

Title source: llm
STIX 2.1

Description

CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/76948
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IV76943
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IV76946
Various Sources vendor-advisory x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IV77007

Scores

EPSS 0.0169
EPSS Percentile 74.7%

Details

CWE
CWE-264
Status published
Products (1)
ibm/powerha_system_mirror
Published Nov 08, 2015
Tracked Since Feb 18, 2026