7.2
CVSSv2

CVE-2016-8972

Published: 15/02/2017 Updated: 31/08/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the bellmail client. IBM APARs: IV91006, IV91007, IV91008, IV91010, IV91011.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

ibm aix 7.1

ibm aix 7.2

ibm aix 6.1

ibm vios 2.2.0.11

ibm vios 2.2.0.12

ibm vios 2.2.1.6

ibm vios 2.2.1.7

ibm vios 2.2.2.6

ibm vios 2.2.2.70

ibm vios 2.2.3.0

ibm vios 2.2.3.52

ibm vios 2.2.3.60

ibm vios 2.2.4.23

ibm vios 2.2.4.30

ibm vios 2.2.0.13

ibm vios 2.2.1.0

ibm vios 2.2.1.8

ibm vios 2.2.2.0

ibm vios 2.2.3.1

ibm vios 2.2.3.2

ibm vios 2.2.3.70

ibm vios 2.2.3.80

ibm vios 2.2.5.0

ibm vios 2.2.5.10

ibm vios 2.2.0.0

ibm vios 2.2.0.10

ibm vios 2.2.1.4

ibm vios 2.2.1.5

ibm vios 2.2.2.3

ibm vios 2.2.2.4

ibm vios 2.2.3.50

ibm vios 2.2.3.51

ibm vios 2.2.4.21

ibm vios 2.2.4.22

ibm vios 2.2.1.1

ibm vios 2.2.1.3

ibm vios 2.2.2.1

ibm vios 2.2.2.2

ibm vios 2.2.3.3

ibm vios 2.2.3.4

ibm vios 2.2.4.0

ibm vios 2.2.4.10

Exploits

#!/usr/bin/sh # # CVE-2016-8972/bellmailrootsh: IBM AIX Bellmail local root # # Affected versions: # AIX 61, 71, 72 # VIOS 22x # # Fileset Lower Level Upper Level KEY # --------------------------------------------------------- # bosnettcpclient 6190 619200 key_w_fs # bosnett ...
IBM AIX versions 61, 71, and 72 suffer from a Bellmail privilege escalation vulnerability ...