4

CVE-2006-3861

IBM Informix Dynamic Server (IDS) before 9.40.xC7 and 10.00 before 10.00.xC3 does not use database creation permissions, which allows remote authenticated users to create arbitrary databases.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Informix Dynamic Server Version 7.31
Ibm ≫ Informix Dynamic Server Version 9.4
Ibm ≫ Informix Dynamic Server Version 9.40.tc5
Ibm ≫ Informix Dynamic Server Version 9.40.uc1
Ibm ≫ Informix Dynamic Server Version 9.40.uc2
Ibm ≫ Informix Dynamic Server Version 9.40.uc3
Ibm ≫ Informix Dynamic Server Version 9.40.uc5
Ibm ≫ Informix Dynamic Server Version 9.40.xc5
Ibm ≫ Informix Dynamic Server Version 10.0
Ibm ≫ Informix Dynamic Server Version 10.0.xc1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.47% 0.706
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/21301
Patch
Vendor Advisory
http://www-1.ibm.com/support/docview.wss?uid=swg21242921
Patch
http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.pdf
http://www.securityfocus.com/archive/1/443133/100/0/threaded
http://www.securityfocus.com/bid/19264
Patch
http://www.vupen.com/english/advisories/2006/3077
http://www.osvdb.org/27692
http://www.securityfocus.com/archive/1/443192/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/28148