First published: Tue Aug 08 2006(Updated: )
IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 does not use database creation permissions, which allows remote authenticated users to create arbitrary databases.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix Dynamic Database Server | =9.40.uc3 | |
IBM Informix Dynamic Database Server | =9.40.uc2 | |
IBM Informix Dynamic Database Server | =9.40.tc5 | |
IBM Informix Dynamic Database Server | =9.40.xc5 | |
IBM Informix Dynamic Database Server | =9.40.uc1 | |
IBM Informix Dynamic Database Server | =10.0.xc1 | |
IBM Informix Dynamic Database Server | =10.0 | |
IBM Informix Dynamic Database Server | =9.4 | |
IBM Informix Dynamic Database Server | =7.31 | |
IBM Informix Dynamic Database Server | =9.40.uc5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-3861 is considered a medium severity vulnerability due to the potential for unauthorized database creation by authenticated users.
To fix CVE-2006-3861, upgrade IBM Informix Dynamic Server to version 9.40.xC7 or 10.00.xC3 or later.
CVE-2006-3861 affects versions of IBM Informix Dynamic Server prior to 9.40.xC7 and 10.00.xC3.
Yes, remote authenticated users can exploit CVE-2006-3861 to create arbitrary databases.
The impact of CVE-2006-3861 on data security includes unauthorized database creation, which may lead to data loss or corruption.