SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  IBM Informix bts_tracefile Remote Code Execution 3

Category: DB-ATTACKS      

The specific flaw exists within the bts_tracefile function. When parsing the trace filename, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of the service account.

References
http://www.zerodayinitiative.com/advisories/ZDI-20-925/


Relevant Information