CVE-2018-1633: High severity IBM Informix Dynamic Server vulnerability
Published Aug 20, 2019
·Updated
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.
Affected Software
12 affected components
IBM Informix Dynamic Server=12.10-fc1
IBM Informix Dynamic Server=12.10-fc10
IBM Informix Dynamic Server=12.10-fc11
IBM Informix Dynamic Server=12.10-fc12
IBM Informix Dynamic Server=12.10-fc2
IBM Informix Dynamic Server=12.10-fc3
IBM Informix Dynamic Server=12.10-fc4
IBM Informix Dynamic Server=12.10-fc5
IBM Informix Dynamic Server=12.10-fc6
IBM Informix Dynamic Server=12.10-fc7
IBM Informix Dynamic Server=12.10-fc8
IBM Informix Dynamic Server=12.10-fc9
Event History
Aug 20, 2019
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-1633?
The severity of CVE-2018-1633 is high.
2
What is the affected software for CVE-2018-1633?
The affected software for CVE-2018-1633 is IBM Informix Dynamic Server Enterprise Edition 12.1.
3
How can a local user gain root privileges through CVE-2018-1633?
A local user logged in with a database administrator user can gain root privileges through a symbolic link vulnerability.
4
How can I fix CVE-2018-1633?
To fix CVE-2018-1633, update to a version of IBM Informix Dynamic Server that does not have the vulnerability.
5
Where can I find more information about CVE-2018-1633?
You can find more information about CVE-2018-1633 at the following links: [link1], [link2], [link3].