VulnerabilityModified
CVE-2006-3858
IBM Informix Dynamic Server (IDS) before 9.40.xC8 and 10.00 before 10.00.xC4 stores passwords in plaintext in shared memory, which allows local users to obtain passwords by reading the memory (product defects 171893, 171894, 173772).
LOW 2.1EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Informix Dynamic Server (IDS) before 9.40.xC8 and 10.00 before 10.00.xC4 stores passwords in plaintext in shared memory, which allows local users to obtain passwords by reading the memory (product defects 171893, 171894, 173772).
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Affected
- ibm/informix dynamic server
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/21301Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21242921Patch
- http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.pdf
- http://www.osvdb.org/27691
- http://www.securityfocus.com/archive/1/443133/100/0/threaded
- http://www.securityfocus.com/archive/1/443195/100/0/threaded
- http://www.securityfocus.com/bid/19264Patch
- http://www.vupen.com/english/advisories/2006/3077
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28132
- http://secunia.com/advisories/21301Patch, Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=swg21242921Patch
- http://www.databasesecurity.com/informix/DatabaseHackersHandbook-AttackingInformix.pdf
- http://www.osvdb.org/27691
- http://www.securityfocus.com/archive/1/443133/100/0/threaded
- http://www.securityfocus.com/archive/1/443195/100/0/threaded
- http://www.securityfocus.com/bid/19264Patch
- http://www.vupen.com/english/advisories/2006/3077
- https://exchange.xforce.ibmcloud.com/vulnerabilities/28132
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.