Junglewise Threat Intelligence

CVE-1999-1119: IBM AIX insecure configuration in anon.ftp installation script

CVE-1999-1119 · Severity: critical · CVSS 10 · Published 1992-04-27

Technologies: IBM Aix. Vendors: IBM.

Executive brief

A vulnerability in the IBM AIX operating system's anonymous FTP setup script allows remote attackers to take full control of the system. By exploiting an insecure configuration created during installation, an unauthorized user can execute commands with high privileges. This could lead to a total compromise of the server, including the theft of sensitive data or the disruption of critical business operations.

Technical details

The vulnerability stems from an insecure default configuration generated by the 'anon.ftp' installation script in IBM AIX. When this script is used to set up anonymous FTP services, it fails to properly restrict permissions or directory access, creating a path for remote, unauthenticated attackers to execute arbitrary commands on the host system. This is a classic configuration-based remote command execution (RCE) vulnerability. Attackers can reach the vulnerable service over the network without any prior authentication. IBM has historically addressed this through patches and updated configuration guidelines.

Affected products

  • IBM AIX

Timeline

  • 1992-04-27: disclosed: Initial publication date
  • 1992-04-27: advisory: NVD published date

References

Related threats