Vulnerability CVE-2012-4857


Published: 2012-12-08

Description:
Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.

Vendor: IBM
Product: Informix dynamic server 
Version:
11.70.xc3
11.70.xc2
11.70.xc1
11.50.xc9
11.50.xc8w4
11.50.xc8w3
11.50.xc8w2
11.50.xc8w1
11.50.xc8
11.50.xc7w4
11.50.xc7w3
11.50.xc7w2
11.50.xc7w1
11.50.xc7
11.50.xc6w4
11.50.xc6w3
11.50.xc6w2
11.50.xc6w1
11.50.xc6
11.50.xc5w4
11.50.xc5w3
11.50.xc5w2
11.50.xc5
11.50.xc4w1
11.50.xc4
11.50.xc3w1
11.50.xc3
11.50.xc2
11.50.xc1
11.50

CVSS2 => (AV:N/AC:L/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9/10
10/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
https://www.ibm.com/support/docview.wss?uid=swg21618994
http://xforce.iss.net/xforce/xfdb/79737

Related CVE
CVE-2019-4403
IBM Connections 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessio...
CVE-2019-4381
IBM i 7.27.3 Clustering could allow a local attacker to obtain sensitive information, caused by the use of advanced node failure detection using the REST API to interface with the HMC. An attacker could exploit this vulnerability to obtain HMC creden...
CVE-2019-4239
IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.
CVE-2019-4070
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to creden...
CVE-2019-4069
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not properly validate file types, allowing an attacker to upload malicious content. IBM X-Force ID: 157014.
CVE-2019-4068
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 is vulnerable to user enumeration, allowing an attacker to brute force into the system. IBM X-Force ID: 157013.
CVE-2019-4067
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 157012.
CVE-2019-4066
IBM Intelligent Operations Center (IOC) 5.1.0 through 5.2.0 could allow an authenciated user to create arbitrary users which could cause ID management issues and result in code execution. IBM X-Force ID: 157011.

Copyright 2019, cxsecurity.com

 

Back to Top