CVE-2018-1632

IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ibmCNA
8.2 HIGH
LOCAL
LOW
HIGH
CVSS:3.0/UI:N/S:C/AC:L/C:H/PR:H/I:H/A:H/AV:L/RL:O/RC:C/E:U
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
ibminformix_dynamic_server
12.10:fc1
ibminformix_dynamic_server
12.10:fc10
ibminformix_dynamic_server
12.10:fc11
ibminformix_dynamic_server
12.10:fc12
ibminformix_dynamic_server
12.10:fc2
ibminformix_dynamic_server
12.10:fc3
ibminformix_dynamic_server
12.10:fc4
ibminformix_dynamic_server
12.10:fc5
ibminformix_dynamic_server
12.10:fc6
ibminformix_dynamic_server
12.10:fc7
ibminformix_dynamic_server
12.10:fc8
ibminformix_dynamic_server
12.10:fc9
𝑥
= Vulnerable software versions