IBM Product Security Update Advisory (CVE-2024-47115)

Overview

 

An update has been released to address vulnerabilities in IBM Products. Users of the affected versions are advised to update to the latest version.
 

 

Affected Products

 

CVE-2024-47115

  • AIX versions: 7.2, 7.3
  • VIOS versions: 3.1, 4.1

 

 

Resolved Vulnerabilities

 

Insufficient input validation could allow local users to execute arbitrary commands on the system (CVE-2024-47115)

 

Vulnerability Patches

Vulnerability patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-47115

  • Updated based on “Remediation/Fixes” on the Referenced site[1]

 

 

Referenced Sites

 

[1] Security Bulletin: AIX is vulnerable to arbitrary command execution due to invscout (CVE-2024-47115)

https://www.ibm.com/support/pages/node/7178033

[2] AIX and VIOS fixes

https://aix.software.ibm.com/aix/efixes/security/invscout_fix7.tar