CVE-2018-1632: High severity IBM Informix Dynamic Server vulnerability
Published Aug 20, 2019
·Updated
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.
Affected Software
12 affected components
IBM Informix Dynamic Server=12.10-fc1
IBM Informix Dynamic Server=12.10-fc10
IBM Informix Dynamic Server=12.10-fc11
IBM Informix Dynamic Server=12.10-fc12
IBM Informix Dynamic Server=12.10-fc2
IBM Informix Dynamic Server=12.10-fc3
IBM Informix Dynamic Server=12.10-fc4
IBM Informix Dynamic Server=12.10-fc5
IBM Informix Dynamic Server=12.10-fc6
IBM Informix Dynamic Server=12.10-fc7
IBM Informix Dynamic Server=12.10-fc8
IBM Informix Dynamic Server=12.10-fc9
Event History
Aug 20, 2019
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1632?
The severity of CVE-2018-1632 is high.
2
How can a local user gain root privileges through CVE-2018-1632?
A local user logged in with database administrator user can gain root privileges through a symbolic link vulnerability in .infxdirs.
3
Which software versions are affected by CVE-2018-1632?
IBM Informix Dynamic Server Enterprise Edition 12.10 versions fc1 to fc12 are affected by CVE-2018-1632.
4
Where can I find more information about CVE-2018-1632?
You can find more information about CVE-2018-1632 on the IBM support website and the IBM X-Force ID.
5
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-1632?
The CWE ID for CVE-2018-1632 is 59.