CVE-2018-1634

CWE-594 documents4 sources
Severity
6.7MEDIUM
EPSS
0.1%
top 81.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 20
Latest updateMay 24

Description

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-cmvv-49j4-8gj6: IBM Informix Dynamic Server Enterprise Edition 122022-05-24
CVEList
CVE-2018-1634: IBM Informix Dynamic Server Enterprise Edition 122019-08-20

💥Exploits & PoCs

1
Exploit-DB
FaceTime - 'readSPSandGetDecoderParams' Stack Corruption2018-11-06
CVE-2018-1634 (MEDIUM CVSS 6.7) | IBM Informix Dynamic Server Enterpr | cvebase.io