CVE-2006-3855IBM Informix Dynamic Server vulnerability

3 documents3 sources
Severity
6.5MEDIUMNVD
EPSS
1.3%
top 20.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 8
Latest updateMay 1

Description

The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _init function in a library, aka "C code UDR."

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 8.0 | Impact: 6.4

Affected Packages1 packages

NVDibm/informix_dynamic_server8 versions+7

Patches

🔴Vulnerability Details

2
GHSA
GHSA-9cg4-76c7-grpg: The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _2022-05-01
CVEList
CVE-2006-3855: The ifx_load_internal function in IBM Informix Dynamic Server (IDS) allows remote authenticated users to execute arbitrary C code via the DllMain or _2006-08-08
CVE-2006-3855 — IBM vulnerability | cvebase