Thanks. Appreciate the response.
Original Message:
Sent: Fri March 21, 2025 12:38 PM
From: Jack Woehr
Subject: IBM urges quick vulnerability patch AIX
@Charles Buckley ... from an IBM Distinguished Engineer:
"AIX 7.1 is impacted. Clients with extended support can open a support case and request a fix."
------------------------------
Jack Woehr
Senior Consultant
Seiden Group LLC
Beulah CO
3038478442
Original Message:
Sent: Fri March 21, 2025 10:49 AM
From: Charles Buckley
Subject: IBM urges quick vulnerability patch AIX
Well.. I don't know if I have the vulnerability on my legacy systems, which is why I am asking if this affects AIX 7.1.
There's no details I have seen on how the exploit works so we can't evaluate the situation. Even if there is a patch, we won't be getting it and there is also the question of the exposure in the meantime before any such patch is released. We have a mitigation plan, but I really, really need to know if we have to pull the trigger on it as it's a bit drastic.
------------------------------
Charles Buckley
Original Message:
Sent: Thu March 20, 2025 06:10 PM
From: Jack Woehr
Subject: IBM urges quick vulnerability patch AIX
"However, versions 7.2 and 7.3 are both vulnerable and should be updated immediately, Big Blue says." - from the cited article.
From AIX Standard Edition_7.1.0 - Withdrawal notification we see:
Lifecycle dates, announcement letters and other information
- GA
- 10-Sep-2010 , 210-200
- EOM
- 23-Nov-2021 , 921-107
- EOS
- 30-Apr-2023 , 921-107
- Extension, Extended, or Sustained Support ends
- 30-Apr-2026
... So I guess if you are vulnerable and have extended support, you'll get a patch.
------------------------------
Jack Woehr
Senior Consultant
Seiden Group LLC
Beulah CO
3038478442
Original Message:
Sent: Thu March 20, 2025 05:38 PM
From: Charles Buckley
Subject: IBM urges quick vulnerability patch AIX
So, we have some legacy systems we are stuck on. Mostly AIX 7.1. Are these systems vulnerable to these exploits?
------------------------------
Charles Buckley
Original Message:
Sent: Thu March 20, 2025 08:50 AM
From: Jack Woehr
Subject: IBM urges quick vulnerability patch AIX
"IBM "strongly recommends" customers running its Advanced Interactive eXecutive (AIX) operating system apply patches after disclosing two critical vulnerabilities, one of which has a perfect 10 severity score."
https://www.theregister.com/2025/03/19/ibm_aix_critical_vulnerabilities/
------------------------------
Jack Woehr
Senior Consultant
Seiden Group LLC
Beulah CO
3038478442
------------------------------