PT-2006-4718 · Ibm · Ibm Informix Dynamic Server
David Litchfield
·
Published
2006-08-17
·
Updated
2018-10-17
·
CVE-2006-3860
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
IBM Informix Dynamic Server (IDS) versions prior to 9.40.xC7
IBM Informix Dynamic Server (IDS) versions prior to 10.00.xC3
Description
The issue allows remote authenticated users to execute arbitrary commands. This can be achieved through the "SET DEBUG FILE" SQL command, as well as the start onpload and dbexp functions.
Recommendations
For versions prior to 9.40.xC7, update to version 9.40.xC7 or later.
For versions prior to 10.00.xC3, update to version 10.00.xC3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Informix Dynamic Server