CVE-2018-1631
published 2019-08-20CVE-2018-1631: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a…
PriorityP428medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.42%
33.7th percentile
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tika | — | — |
| ibm | informix_dynamic_server | — | — |
| ibm | informix_dynamic_server_enterprise_edition | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv3.08.2HIGHCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_apache9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-329c-jrv3-6h96: IBM Informix Dynamic Server Enterprise Edition 12
ghsa_unreviewed·2022-05-24
CVE-2018-1631 [HIGH] CWE-59 GHSA-329c-jrv3-6h96: IBM Informix Dynamic Server Enterprise Edition 12
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.
Apache
Apache tika: CVE-2018-7489
vendor_apache·CVSS 9.8
CVE-2018-7489 [CRITICAL] Apache tika: CVE-2018-7489
Apache tika: CVE-2018-7489
and TIKA-2634 Jackson - Deserialization vulnerability Richard Cyganiak (notified Tika team) ?-1.17 PDFBOX-3919 Apache PDFBox - Infinite loop Hanno Böck and Andreas Bogk ?-1.16 TIKA-2115 Apache POI - OOM parsing OLE object Thomas Galla ?-1.15 COMPRESS-382 Commons Compress - OOM detecting corrupt LZMA Luís Filipe Nassif ?-1.15 COMPRESS-386 and TIKA-1631 Commons Compress - OOM detecting corrupt x-compress Pavel Micka ?-1.15 TIKA-2045 and TIKA-3442 Apache PDFBox - OOM in font caching Egbert ?-1.13 TIKA-1866 and TIKA-954 Apache POI - OOM in DOCX and PPTX because of bug in Piccolo parser Rob Tulloh and Shawn Johnson ?-1.13 TIKA-2040 GC-Overload and OOM in CHMParser Luís Filipe Nassif ?-1.13
Apache
Apache tika: CVE-2018-19362
vendor_apache·CVSS 9.8
CVE-2018-19362 [CRITICAL] Apache tika: CVE-2018-19362
Apache tika: CVE-2018-19362
FaxterXML jackson-databind may allow attackers to have unspecified impact from polymorphic deserialization Pat Cashman (notified Tika team) ?-1.20 Acronyms and Terms Command Execution -- A malicious client could execute anything on tika-server's commandline Deserialization Vulnerability -- OWASP's Cheat Sheet . A malicious actor could run arbitrary code on your computer. OOM -- Out of Memory Error -- Parsers may allocate more memory than is available. This can sometimes be caused by parsers not performing sanity checks before allocation. See, for example: TIKA-1631 XXE -- XML External Entity Processing A malicious client could access data on your system. Apache Tika Introduction Download Contribute Mailing Lists Tika Wiki Tika Server Wiki Issue Tracker Security
No detection rules found.
No public exploits indexed.
http://www.ibm.com/support/docview.wss?uid=ibm10964987https://exchange.xforce.ibmcloud.com/vulnerabilities/144431https://security.netapp.com/advisory/ntap-20190903-0002/http://www.ibm.com/support/docview.wss?uid=ibm10964987https://exchange.xforce.ibmcloud.com/vulnerabilities/144431https://security.netapp.com/advisory/ntap-20190903-0002/
2019-08-20
Published