CVE-2015-5005: IBM Powerha System Mirror

High severity, CVSS 8.5. EPSS: 1.7% chance of exploitation in the next 30 days.

CSPOC in IBM PowerHA SystemMirror on AIX 6.1 and 7.1 allows remote authenticated users to perform an "su root" action by leveraging presence on the cluster-wide password-change list.

Affected products

  • IBM Powerha System Mirror: any version

Published 2015-11-08. Last modified 2026-06-17.