8.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Description
IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to write arbitrary files on the system.
Basic Information
ID
CVE-2025-36236
Source
ibm
Published
Nov 13, 2025 at 22:01
Affected Product
Vendor
IBM
Product
AIX
Version
7.2
Affected Versions
IBM AIX 7.2
IBM AIX 7.3
IBM VIOS 3.1
IBM VIOS 4.1
IBM AIX 7.3
IBM VIOS 3.1
IBM VIOS 4.1