|
AIX contains a weakness that is triggered by the passwd command not asking for the current password when modifying the user's current password. This violates password policy for most organizations, as an attacker that gains access to an account (e.g., via exploit) could then manipulate the password without knowledge of the current one.
|