CVE-2025-36236
8.2IBM · AIX, VIOS
The IBM AIX and VIOS NIM server service (nimesis) is vulnerable to path traversal, allowing a remote, unauthenticated attacker to write arbitrary files to the system via a crafted URL request.
Executive summary
IBM AIX and VIOS systems are vulnerable to a remote path traversal flaw that permits unauthorized file writes, posing a high risk to system integrity.
Vulnerability
The nimesis service on the specified IBM platforms fails to properly sanitize path inputs, allowing an unauthenticated remote attacker to perform directory traversal and write arbitrary files. The vulnerability stems from improper input validation within the NIM server component.
Business impact
Successful exploitation of this vulnerability allows an attacker to overwrite critical system files or configurations, which can lead to unauthorized code execution, system instability, or full compromise of the affected host. With a CVSS score of 8.2, this vulnerability is classified as High severity because it is network exploitable without authentication, making it a prime target for automated exploitation.
Remediation
Immediate Action: Apply the vendor-supplied security patches detailed in the official IBM security bulletin (https://www.ibm.com/support/pages/node/7251173) immediately.
Proactive Monitoring: Monitor system logs for unusual file write operations or suspicious URL patterns directed at the nimesis service port.
Compensating Controls: Implement network access controls or a Web Application Firewall to restrict traffic to the NIM server service to only known, authorized IP addresses.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for remote, unauthenticated system compromise, this vulnerability represents a significant security risk. Administrators must prioritize the application of the IBM patches to the affected AIX and VIOS environments to prevent potential unauthorized file manipulation and system takeover.
More IBM CVEs
Sources
Originally found and disclosed by These vulnerabilities were reported to IBM by Oneconsult AG (https://oneconsult.com/), Jan Alsenz., per the CVE Program record.