HTTP: IBM Informix OpenAdmin Tool welcomeService.php Command Execution

This signature detects attempts to exploit a known vulnerability in the welcomeService.php script of IBM Informix OpenAdmin Tool, packaged as part of Dynamic Server. Successful exploitation could result in code execution under the security context of SYSTEM.

Extended Description

IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390.

Affected Products

Ibm informix_open_admin_tool

Short Name
HTTP:IBM-INFORMIX-OPENADMIN-CE
Severity
Critical
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2017-1092 Command Execution IBM Informix OpenAdmin Tool welcomeService.php
Release Date
02/15/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
False Positive
Unknown
Vendors

Ibm

CVSS Score

10.0

Found a potential security threat?