VulnerabilityModified
CVE-2017-1310
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server.
MEDIUM 6.5EPSS 1.69%
Does this matter?
Lower severity and a low EPSS score (1.69%). Track it; it rarely justifies an emergency change on its own.
Description
IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.69% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- ibm/informix dynamic server
- Source
- psirt@us.ibm.com
References
- http://www.ibm.com/support/docview.wss?uid=swg22004930Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99309Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125569VDB Entry, Vendor Advisory
- http://www.ibm.com/support/docview.wss?uid=swg22004930Patch, Vendor Advisory
- http://www.securityfocus.com/bid/99309Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038803
- https://exchange.xforce.ibmcloud.com/vulnerabilities/125569VDB Entry, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.