CVE-2008-0369
 
Severity Score
6.9
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Multiple unspecified programs in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allow local users to create arbitrary files by specifying the target file in the SQLIDEBUG environment variable, whose ownership is changed to the user invoking the programs.
MĂșltiples programas no especificados en IBM Informix Dynamic Server (IDS) versiones 10.x anteriores a 10.00.xC8, permiten a usuarios locales crear archivos arbitrarios especificando el archivo de destino en la variable de entorno SQLIDEBUG, cuya propiedad es cambiada por el usuario que invoca los programas.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-01-18 CVE Reserved
- 2008-01-18 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=650 | Third Party Advisory | |
http://www-1.ibm.com/support/docview.wss?uid=swg27011556 | X_refsource_confirm | |
http://www.securityfocus.com/bid/27328 | Vdb Entry | |
http://www.securitytracker.com/id?1019237 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39751 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/40009 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/28534 | 2017-08-08 | |
http://www-1.ibm.com/support/docview.wss?uid=swg1IC54309 | 2017-08-08 | |
http://www.vupen.com/english/advisories/2008/0169 | 2017-08-08 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Informix Dynamic Server Search vendor "Ibm" for product "Informix Dynamic Server" | 10.00 Search vendor "Ibm" for product "Informix Dynamic Server" and version "10.00" | - |
Affected
|