CVE-2015-5005
IBM PowerHA SystemMirror - Authenticated Privilege Escalation via CSPOC
Title source: llmDescription
CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
http://aix.software.ibm.com/aix/efixes/security/powerha_advisory.asc
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/76948
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IV76943
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IV76946
Various Sources vendor-advisory
x_refsource_aixapar
http://www-01.ibm.com/support/docview.wss?uid=isg1IV77007
Scores
EPSS
0.0169
EPSS Percentile
74.7%
Details
CWE
CWE-264
Status
published
Products (1)
ibm/powerha_system_mirror
Published
Nov 08, 2015
Tracked Since
Feb 18, 2026