CVE-2025-36244
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-09-16
Last updated on: 2025-10-17
Assigner: IBM Corporation
Description
Description
IBM AIX 7.2, 7.3, IBM VIOS 3.1, and 4.1, when configured to use Kerberos network authentication, could allow a local user to write to files on the system with root privileges due to improper initialization of critical variables.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ibm | vios | 3.1 |
| ibm | vios | 4.1 |
| ibm | aix | 7.2 |
| ibm | aix | 7.3 |
| ibm | aix | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-454 | The product initializes critical internal variables or data stores using inputs that can be modified by untrusted actors. |