Impact
A local privilege escalation flaw exists in the oninit setuid-root utility of IBM Informix Dynamic Server. The vulnerability arises from improper access control in the setuid component, allowing a user with local access to elevate privileges to root. With root access, an attacker can execute arbitrary code and compromise the entire system, representing a significant risk to confidentiality, integrity, and availability.
Affected Systems
The flaw affects IBM Informix Dynamic Server versions 14.10 and 15.0. IBM released fixes for 14.10.xC13W13 and 15.0.1.14. All other versions not listed in the CNA data are not confirmed to be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. EPSS data is not available, so the likelihood of exploitation remains uncertain, and the vulnerability is not currently listed in CISA's KEV catalog. The attack vector is local and likely requires the attacker to run or influence the oninit utility, as the vulnerability is tied to a setuid-root binary. If an attacker can execute a malicious command or replace assets used by oninit, they can gain root privileges and deploy arbitrary code on the affected system.
OpenCVE Enrichment