Risk | Low |
Patch available | NO |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2016-6038 |
CWE-ID | CWE-200 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software Subscribe |
IBM AIX Operating systems & Components / Operating system |
Vendor | IBM Corporation |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU643
Risk: Low
CVSSv3.1: 4.9 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:C]
CVE-ID: CVE-2016-6038
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a remote user to obtain potentially sensitive information on the target system.
The weakness exists due to directory traversal flaw. By submission of specially crafted URL attackers can easily view arbitrary files.
Successfull exploitation of the vulnerability may result in information disclosure on the vulnerable system.
No solution resolving the vulnerability is available.
IBM AIX: 5.3 - 7.1
External linkshttp://aix.software.ibm.com/aix/efixes/security/pconsole_mitigation.asc
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.