VNC is not considered a particularly secure protocol and can come up on vulnerability scans. For this reason VNC is normally disabled on each server.
Note that, on Linux, VNC can be compiled to use SSL which does make it more secure. Unfortunately an RPM for VNC with SSL doesn't currently exist for AIX, and compiling VNC on AIX is not trivial.
Remmina