CVE-2006-3859

IBM Informix Dynamic Server - Privilege Escalation

Title source: llm
STIX 2.1

Description

IBM Informix Dynamic Server (IDS) allows remote authenticated users to create and overwrite arbitrary files via the (1) LOTOFILE and (2) trl_tracefile_set functions, and the (3) "SET DEBUG FILE" commands.

References (5)

Core 5
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1408
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443133/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/28383
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/443216/100/0/threaded

Scores

EPSS 0.0111
EPSS Percentile 62.6%

Details

Status published
Products (4)
ibm/informix_dynamic_database_server 9.40.tc7
ibm/informix_dynamic_database_server 9.40.tc8
ibm/informix_dynamic_database_server 10.00.tc4
ibm/informix_dynamic_database_server 10.00.tc5
Published Aug 17, 2006
Tracked Since Feb 18, 2026