Remote Code Execution Vulnerability in IBM Informix Dynamic Server Enterprise Edition
CVE-2018-1634

8.2HIGH

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 August 2019

Summary

A local privilege escalation vulnerability has been identified in IBM Informix Dynamic Server Enterprise Edition 12.1. This issue enables a local user, authenticated as a database administrator, to potentially gain elevated root privileges through a symbolic link flaw in the infos.DBSERVERNAME configuration file. Exploiting this vulnerability may allow unauthorized actions within the system, posing a significant risk to data integrity and security. Organizations employing this version of Informix are advised to evaluate their security posture and implement necessary patches to mitigate potential risks.

Affected Version(s)

Informix Dynamic Server Enterprise Edition 12.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.