CVE-2018-1634: High severity IBM Informix Dynamic Server vulnerability
IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-1634?
CVE-2018-1634 is a vulnerability in IBM Informix Dynamic Server Enterprise Edition 12.1 that could allow a local user with database administrator privileges to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME.
How severe is CVE-2018-1634?
CVE-2018-1634 has a severity rating of 6.7 (high).
How does CVE-2018-1634 affect IBM Informix Dynamic Server?
CVE-2018-1634 affects IBM Informix Dynamic Server Enterprise Edition 12.1 versions 12.10-fc1 to 12.10-fc9.
What is the Common Weakness Enumeration (CWE) associated with CVE-2018-1634?
CVE-2018-1634 is associated with CWE-59, which is a vulnerability that occurs when an attacker can change the resource path used in file operations.
Are there any references for CVE-2018-1634?
Yes, you can find more information about CVE-2018-1634 at the following references: [IBM Support Document](http://www.ibm.com/support/docview.wss?uid=ibm10964987), [IBM X-Force](https://exchange.xforce.ibmcloud.com/vulnerabilities/144437), [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20190903-0002/).