IBM Informix Dynamic Server Windows XP Simple File Sharing Authentication Bypass Vulnerability
BID:15451
Info
IBM Informix Dynamic Server Windows XP Simple File Sharing Authentication Bypass Vulnerability
| Bugtraq ID: | 15451 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 16 2005 12:00AM |
| Updated: | Nov 16 2005 12:00AM |
| Credit: | Discovery is credited to David Litchfield of NGSSoftware. |
| Vulnerable: |
IBM Informix IDS 9.40 .UC3 IBM Informix IDS 9.40 .UC2 IBM Informix IDS 9.40 .UC1 IBM Informix IDS 9.3 |
| Not Vulnerable: | |
Discussion
IBM Informix Dynamic Server Windows XP Simple File Sharing Authentication Bypass Vulnerability
IBM Informix Dynamic Server (IBM Informix IDS) is affected by an authentication bypass vulnerability when run on Microsoft Windows XP computers that have Simple File Sharing enabled.
This vulnerability may let attackers gain unauthorized access to the database using the Windows XP Guest account.
The researcher who discovered this issue has not provided a conclusive list of affected IBM Informix Dynamic Server products. For the time being, all versions that run on Windows XP are assumed to be affected. If contrary information is made available, this BID will be updated accordingly.
IBM Informix Dynamic Server (IBM Informix IDS) is affected by an authentication bypass vulnerability when run on Microsoft Windows XP computers that have Simple File Sharing enabled.
This vulnerability may let attackers gain unauthorized access to the database using the Windows XP Guest account.
The researcher who discovered this issue has not provided a conclusive list of affected IBM Informix Dynamic Server products. For the time being, all versions that run on Windows XP are assumed to be affected. If contrary information is made available, this BID will be updated accordingly.
Exploit / POC
IBM Informix Dynamic Server Windows XP Simple File Sharing Authentication Bypass Vulnerability
There is no exploit required.
There is no exploit required.
Solution / Fix
IBM Informix Dynamic Server Windows XP Simple File Sharing Authentication Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
IBM Informix Dynamic Server Windows XP Simple File Sharing Authentication Bypass Vulnerability
References:
References: