-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 ##################################################### ## N C S C ~ B E V E I L I G I N G S A D V I E S ## ##################################################### Titel : Meerdere kwetsbaarheden verholpen in IBM AIX en IBM PowerVM VIOS Advisory ID : NCSC-2026-0321 Versie : 1.00 Kans : medium CVE ID : CVE-2025-12817, CVE-2025-12818, CVE-2025-15649, CVE-2026-2003, CVE-2026-2004, CVE-2026-2005, CVE-2026-2006, CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475, CVE-2026-6477, CVE-2026-6478, CVE-2026-6637, CVE-2026-8368, CVE-2026-8400, CVE-2026-8829, CVE-2026-12087, CVE-2026-14970, CVE-2026-15061, CVE-2026-15065, CVE-2026-15068, CVE-2026-15078, CVE-2026-16243, CVE-2026-16439, CVE-2026-16441, CVE-2026-16656, CVE-2026-16686, CVE-2026-16690, CVE-2026-16703, CVE-2026-16706, CVE-2026-16814, CVE-2026-16816, CVE-2026-16817, CVE-2026-16818, CVE-2026-16819, CVE-2026-16822, CVE-2026-16824, CVE-2026-16825, CVE-2026-16827, CVE-2026-16829, CVE-2026-16831, CVE-2026-16833, CVE-2026-16834, CVE-2026-16836, CVE-2026-16837, CVE-2026-16838, CVE-2026-16839, CVE-2026-16840, CVE-2026-16841, CVE-2026-16842, CVE-2026-16844, CVE-2026-16845, CVE-2026-16846, CVE-2026-16847, CVE-2026-16848, CVE-2026-16849, CVE-2026-16850, CVE-2026-16851, CVE-2026-16852, CVE-2026-16855, CVE-2026-16857, CVE-2026-16862, CVE-2026-16864, CVE-2026-16865, CVE-2026-16866, CVE-2026-16869, CVE-2026-16872, CVE-2026-16873, CVE-2026-16874, CVE-2026-16875, CVE-2026-16877, CVE-2026-16882, CVE-2026-16883, CVE-2026-16885, CVE-2026-16886, CVE-2026-16888, CVE-2026-16890, CVE-2026-16891, CVE-2026-16894, CVE-2026-16897, CVE-2026-16901, CVE-2026-16903, CVE-2026-16909, CVE-2026-16911, CVE-2026-16913, CVE-2026-16914, CVE-2026-16917, CVE-2026-16919, CVE-2026-16922, CVE-2026-16923, CVE-2026-16924, CVE-2026-16925, CVE-2026-16926, CVE-2026-16927, CVE-2026-16928, CVE-2026-16932, CVE-2026-16934, CVE-2026-16935, CVE-2026-16936, CVE-2026-16937, CVE-2026-16943, CVE-2026-16944, CVE-2026-16945, CVE-2026-16946, CVE-2026-16951, CVE-2026-16952, CVE-2026-16958, CVE-2026-16964, CVE-2026-16972, CVE-2026-16973, CVE-2026-16980, CVE-2026-16989, CVE-2026-16991, CVE-2026-16996, CVE-2026-16997, CVE-2026-17000, CVE-2026-17003, CVE-2026-17006, CVE-2026-17007, CVE-2026-17009, CVE-2026-17024, CVE-2026-17040, CVE-2026-17060, CVE-2026-17118, CVE-2026-17120, CVE-2026-17121, CVE-2026-17122, CVE-2026-17124, CVE-2026-17136, CVE-2026-17138, CVE-2026-17141, CVE-2026-17142, CVE-2026-17145, CVE-2026-17152, CVE-2026-17157, CVE-2026-17159, CVE-2026-17160, CVE-2026-17163, CVE-2026-17165, CVE-2026-17168, CVE-2026-17170, CVE-2026-17171, CVE-2026-17195, CVE-2026-17422, CVE-2026-17423, CVE-2026-17424, CVE-2026-17425, CVE-2026-17436, CVE-2026-18670, CVE-2026-18716, CVE-2026-18822, CVE-2026-18824, CVE-2026-18828, CVE-2026-18832, CVE-2026-18835, CVE-2026-18840, CVE-2026-18842, CVE-2026-19437, CVE-2026-19442, CVE-2026-19446, CVE-2026-19448, CVE-2026-19449, CVE-2026-19653, CVE-2026-19783, CVE-2026-22007, CVE-2026-22013, CVE-2026-22016, CVE-2026-22018, CVE-2026-22021, CVE-2026-34268, CVE-2026-41254, CVE-2026-46968, CVE-2026-47010, CVE-2026-47021, CVE-2026-47027, CVE-2026-47057, CVE-2026-47058, CVE-2026-47059, CVE-2026-47063, CVE-2026-48959, CVE-2026-48962, CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, CVE-2026-60002, CVE-2026-60147 (Details over de kwetsbaarheden kunt u vinden op de Mitre website: https://cve.mitre.org/cve/) Schade : high Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Relative Path Traversal Improper Link Resolution Before File Access ('Link Following') UNIX Symbolic Link (Symlink) Following External Control of File Name or Path Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Improper Control of Generation of Code ('Code Injection') Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') Stack-based Buffer Overflow Heap-based Buffer Overflow Buffer Underwrite ('Buffer Underflow') Out-of-bounds Read Wrap-around Error Improper Validation of Array Index Use of Externally-Controlled Format String Integer Overflow or Wraparound Integer Underflow (Wrap or Wraparound) Exposure of Sensitive Information to an Unauthorized Actor Use of Inherently Dangerous Function Uncaught Exception Improper Privilege Management Improper Access Control Improper Authorization Improper Authentication Improper Certificate Validation Improper Restriction of Excessive Authentication Attempts Cleartext Storage of Sensitive Information Cleartext Transmission of Sensitive Information Use of a Broken or Risky Cryptographic Algorithm Improper Verification of Cryptographic Signature Use of Less Trusted Source Improperly Implemented Security Check for Standard Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Time-of-check Time-of-use (TOCTOU) Race Condition Divide By Zero Covert Timing Channel Uncontrolled Resource Consumption Improper Resource Shutdown or Release Inefficient Algorithmic Complexity Use After Free Untrusted Search Path Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') NULL Pointer Dereference Deserialization of Untrusted Data Insufficiently Protected Credentials Improper Restriction of XML External Entity Reference Uncontrolled Recursion Protection Mechanism Failure Incorrect Behavior Order Improper Neutralization Reliance on Undefined, Unspecified, or Implementation- Defined Behavior Allocation of Resources Without Limits or Throttling Out-of-bounds Write Buffer Access with Incorrect Length Value Untrusted Pointer Dereference Expired Pointer Dereference Access of Resource Using Incompatible Type ('Type Confusion') Missing Authorization Use of Uninitialized Resource Improper Validation of Specified Quantity in Input Improper Validation of Specified Index, Position, or Offset in Input Improper Validation of Specified Type of Input Inefficient Regular Expression Complexity Uitgiftedatum : 20260821 Toepassing : IBM AIX IBM AIX, PowerVM VIOS Versie(s) : Platform(s) : Beschrijving IBM heeft kwetsbaarheden verholpen in AIX en PowerVM VIOS. Ook heeft IBM eerdere kwetsbaarheden in, onder andere, DB2, WebSphere, Oracle producten als Java en GraalVM, PostgreSQL, OpenSSH en Perl verholpen voor de producten geproduceerd voor AIX. Een kwaadwillende kan de kwetsbaarheden misbruiken om aanvallen uit te voeren die kunnen leiden tot de volgende categorieën schade: - Denial-of-Service - Omzeilen van een beveiligingsmaatregel - Uitvoer van willekeurige code (root/admin-rechten) - Uitvoer van willekeurige code (gebruikersrechten) - Toegang tot gevoelige gegevens - Manipulatie van gegevens - Verhogen van privileges Mogelijke oplossingen De leveranciers hebben updates uitgebracht voor PostgreSQL, IBM AIX, IBM PowerVM VIOS, Perl modules, OpenSSH, Oracle Java SE, Oracle GraalVM, OpenJDK, IBM Db2 Client en Server, en Oracle Communications Cloud Native Core Certificate Management om de beschreven kwetsbaarheden te verhelpen. Zie bijgevoegde referenties voor meer informatie. Referenties: Reference https://www.ibm.com/support/pages/node/7283858 Vrijwaringsverklaring Door gebruik van deze security advisory gaat u akkoord met de navolgende voorwaarden. Ondanks dat het NCSC de grootst mogelijke zorg heeft betracht bij de samenstelling van dit beveiligingsadvies, kan het NCSC niet instaan voor de volledigheid, juistheid of (voortdurende) actualiteit van dit beveiligingsadvies. De informatie in dit beveiligingsadvies is uitsluitend bedoeld als algemene informatie voor professionele partijen. Aan de informatie in dit beveiligingsadvies kunnen geen rechten worden ontleend. Het NCSC en de Staat zijn niet aansprakelijk voor enige schade ten gevolge van het gebruik of de onmogelijkheid van het gebruik van dit beveiligingsadvies, waaronder begrepen schade ten gevolge van de onjuistheid of onvolledigheid van de informatie in dit beveiligingsadvies. Op dit beveiligingsadvies is Nederlands recht van toepassing. Alle geschillen in verband met en/of voortvloeiend uit dit beveiligingsadvies zullen worden voorgelegd aan de exclusief bevoegde rechter te Den Haag. Deze rechtskeuze geldt tevens voor de voorzieningenrechter in kort geding. -----BEGIN PGP SIGNATURE----- iQGzBAEBCgAdFiEEGSwziqblmmRNtImqgupWoL0ZhGEFAmqICLoACgkQgupWoL0Z hGGnlwwAyngMm+hAh8A7Ptj+f9mvStfwsb0WAqOu2yiq/cLWYTZNPjCtarcjWyZD gC1GymYUAAz5dcbpZm4qcGVp4+/OZMgxy6eBgIHuONI6TWxCITWHJkraykqMURHx l1UoCHeoPRGR6ygcQXW+h5ygUgsyCX2Jnc8DmIM4PHcU1CBJxOUAqLg4X7BcJukI B57QnV7AUAyF08JFSyvAEX8yJvTOrcqAlXd7+6DjcGxCeIKBD+CDtt+stq6bZUCx mE6wCkl0i2rmqKQu1wKpWFmkVYEIR4PQu0WOhzyrwSLENllLUwwtoFoBo+HnwrKP RWm3WEoSU+TkS9RGr/4CfxG+k17sLWQ7+oAjNuoWepMFnxjP+Wq1e21zd9b9XZLP irnpoRDhJ3gYmht3wGn/jCnlnAA8uUFWQ9xfNW2WVRizAswcGTrwkTiUXpmmgo72 cxvW2LQ1c5BpQH/IPj6VNSEXeLIZZ3R5hAzCVJMasA6BSwnnNOyi2g7gqV/8HRRC avz5Z3qK =D5p9 -----END PGP SIGNATURE-----