IBM Informix Dynamic Server (IDS) before 9.40.xC3 allows local users to (1) create or overwrite files via the /001 log file to onedcu or (2) read arbitrary files via a symlink attack on a file in /tmp to onshowaudit.
2004-12-31T05:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 3.6 (LOW)
AV:L/AC:L/Au:N/C:P/I:P/A:N
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | ibm | informix_dynamic_server | 9.40.uc1 | Yes |
Application | ibm | informix_dynamic_server | 9.40.uc2 | Yes |
Application | ibm | informix_extended_parallel_server | 8.40_uc1 | Yes |
Application | ibm | informix_extended_parallel_server | 8.40_uc2 | Yes |