The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 02:41
Type | Values Removed | Values Added |
---|---|---|
References | () http://www-01.ibm.com/support/docview.wss?uid=swg21978598 - Patch, Vendor Advisory | |
References | () http://www.securitytracker.com/id/1035286 - | |
References | () http://zerodayinitiative.com/advisories/ZDI-16-208/ - | |
References | () http://zerodayinitiative.com/advisories/ZDI-16-209/ - | |
References | () http://zerodayinitiative.com/advisories/ZDI-16-210/ - |
Information
Published : 2016-03-28 23:59
Updated : 2024-11-21 02:41
NVD link : CVE-2016-0226
Mitre link : CVE-2016-0226
CVE.ORG link : CVE-2016-0226
JSON object : View
Products Affected
ibm
- informix_dynamic_server
microsoft
- windows
CWE
CWE-284
Improper Access Control