CVE-2018-1632Link Following in IBM Informix Dynamic Server Enterprise Edition

CWE-59Link Following3 documents3 sources
Severity
6.7MEDIUMNVD
EPSS
0.1%
top 81.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20
Latest updateMay 24

Description

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-7p8h-3xw2-w6jw: IBM Informix Dynamic Server Enterprise Edition 122022-05-24
CVEList
CVE-2018-1632: IBM Informix Dynamic Server Enterprise Edition 122019-08-20
CVE-2018-1632 — Link Following in IBM | cvebase