IBM Product Security Update Advisory (CVE-2024-47115)
Overview
An update has been released to address vulnerabilities in IBM Products. Users of the affected versions are advised to update to the latest version.
Affected Products
CVE-2024-47115
- AIX versions: 7.2, 7.3
- VIOS versions: 3.1, 4.1
Resolved Vulnerabilities
Insufficient input validation could allow local users to execute arbitrary commands on the system (CVE-2024-47115)
Vulnerability Patches
Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2024-47115
- Updated based on “Remediation/Fixes” on the Referenced site[1]
Referenced Sites
[1] Security Bulletin: AIX is vulnerable to arbitrary command execution due to invscout (CVE-2024-47115)
https://www.ibm.com/support/pages/node/7178033
[2] AIX and VIOS fixes
https://aix.software.ibm.com/aix/efixes/security/invscout_fix7.tar