AIX : Multiple Vulnerabilities (IJ59566)

medium Nessus Plugin ID 338726

Synopsis

The remote AIX host is missing a security patch.

Description

The version of AIX installed on the remote host is prior to APAR IJ59566. It is, therefore, affected by multiple vulnerabilities as referenced in the IJ59566 advisory.

- IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM SDK, Java Technology Edition, may allow a malicious IIOP server to induce loading and instantation of arbitrary classes. (CVE-2026-8400)

- IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. (CVE-2026-18828)

- IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. (CVE-2026-16872, CVE-2026-17122, CVE-2026-17138)

- IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. (CVE-2026-16841, CVE-2026-16862, CVE-2026-16864, CVE-2026-16885, CVE-2026-16894, CVE-2026-16913, CVE-2026-17157)

- IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability. (CVE-2026-17118)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Please apply the appropriate interim fix per APAR IJ59566.

See Also

https://www.ibm.com/support/pages/apar/IJ59566

https://www.ibm.com/support/pages/node/7283858

Plugin Details

Severity: Medium

ID: 338726

File Name: aix_IJ59566.nasl

Version: 1.1

Type: Local

Published: 8/21/2026

Updated: 8/21/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.4

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-8400

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 5.6

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:H/VA:L/SC:L/SI:H/SA:N

CVSS Score Source: CVE-2026-16441

Vulnerability Information

Required KB Items: Host/local_checks_enabled, Host/AIX/version, Host/AIX/lslpp

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/15/2026

Vulnerability Publication Date: 11/13/2025

Reference Information

CVE: CVE-2025-12817, CVE-2025-12818, CVE-2025-15649, CVE-2026-12087, CVE-2026-14970, CVE-2026-15061, CVE-2026-15065, CVE-2026-15068, CVE-2026-15078, CVE-2026-16243, CVE-2026-16439, CVE-2026-16441, CVE-2026-16656, CVE-2026-16686, CVE-2026-16690, CVE-2026-16703, CVE-2026-16706, CVE-2026-16814, CVE-2026-16816, CVE-2026-16818, CVE-2026-16819, CVE-2026-16821, CVE-2026-16822, CVE-2026-16824, CVE-2026-16825, CVE-2026-16827, CVE-2026-16829, CVE-2026-16831, CVE-2026-16833, CVE-2026-16834, CVE-2026-16836, CVE-2026-16837, CVE-2026-16838, CVE-2026-16839, CVE-2026-16840, CVE-2026-16841, CVE-2026-16842, CVE-2026-16844, CVE-2026-16845, CVE-2026-16846, CVE-2026-16847, CVE-2026-16848, CVE-2026-16849, CVE-2026-16850, CVE-2026-16855, CVE-2026-16857, CVE-2026-16862, CVE-2026-16864, CVE-2026-16865, CVE-2026-16866, CVE-2026-16869, CVE-2026-16872, CVE-2026-16873, CVE-2026-16874, CVE-2026-16875, CVE-2026-16877, CVE-2026-16882, CVE-2026-16883, CVE-2026-16885, CVE-2026-16886, CVE-2026-16888, CVE-2026-16890, CVE-2026-16891, CVE-2026-16894, CVE-2026-16897, CVE-2026-16901, CVE-2026-16903, CVE-2026-16909, CVE-2026-16911, CVE-2026-16913, CVE-2026-16914, CVE-2026-16917, CVE-2026-16919, CVE-2026-16922, CVE-2026-16923, CVE-2026-16924, CVE-2026-16925, CVE-2026-16926, CVE-2026-16927, CVE-2026-16928, CVE-2026-16932, CVE-2026-16934, CVE-2026-16935, CVE-2026-16936, CVE-2026-16937, CVE-2026-16943, CVE-2026-16944, CVE-2026-16945, CVE-2026-16946, CVE-2026-16958, CVE-2026-16964, CVE-2026-16972, CVE-2026-16973, CVE-2026-16980, CVE-2026-16989, CVE-2026-16991, CVE-2026-16996, CVE-2026-16997, CVE-2026-17000, CVE-2026-17003, CVE-2026-17006, CVE-2026-17007, CVE-2026-17009, CVE-2026-17024, CVE-2026-17040, CVE-2026-17060, CVE-2026-17118, CVE-2026-17120, CVE-2026-17121, CVE-2026-17122, CVE-2026-17124, CVE-2026-17136, CVE-2026-17138, CVE-2026-17141, CVE-2026-17142, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, CVE-2026-17159, CVE-2026-17160, CVE-2026-17163, CVE-2026-17165, CVE-2026-17168, CVE-2026-17170, CVE-2026-17171, CVE-2026-17195, CVE-2026-17422, CVE-2026-17423, CVE-2026-17424, CVE-2026-17425, CVE-2026-17436, CVE-2026-18670, CVE-2026-18716, CVE-2026-18822, CVE-2026-18824, CVE-2026-18828, CVE-2026-18832, CVE-2026-18835, CVE-2026-18840, CVE-2026-18842, CVE-2026-19442, CVE-2026-19446, CVE-2026-19448, CVE-2026-19449, CVE-2026-19653, CVE-2026-19783, CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268, CVE-2026-41254, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-48959, CVE-2026-48962, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002, CVE-2026-60147, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6637, CVE-2026-8368, CVE-2026-8400, CVE-2026-8829