Ibm Informix Dynamic Server vulnerabilities

50 known vulnerabilities affecting ibm/informix_dynamic_server.

Total CVEs
50
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH14MEDIUM23LOW4

Vulnerabilities

Page 1 of 3
CVE-2024-45675HIGHCVSS 7.8fixed in 14.10v14.102025-12-02
CVE-2024-45675 [HIGH] CWE-309 CVE-2024-45675: IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix se IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.
cvelistv5nvd
CVE-2024-49342HIGHCVSS 7.5v12.10v14.102025-07-28
CVE-2024-49342 [HIGH] CWE-307 CVE-2024-49342: IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could al IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
cvelistv5nvd
CVE-2024-49343MEDIUMCVSS 5.4v12.10v14.102025-07-28
CVE-2024-49343 [MEDIUM] CWE-80 CVE-2024-49343: IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site.
cvelistv5nvd
CVE-2025-1991HIGHCVSS 7.5v12.10v14.10+1 more2025-06-28
CVE-2025-1991 [HIGH] CWE-191 CVE-2025-1991: IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets.
cvelistv5nvd
CVE-2023-28523HIGHCVSS 7.8v12.10v14.10+1 more2023-12-09
CVE-2023-28523 [HIGH] CWE-122 CVE-2023-28523: IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, cause IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753.
cvelistv5nvd
CVE-2023-28527MEDIUMCVSS 5.5v12.10v14.10+1 more2023-12-09
CVE-2023-28527 [MEDIUM] CWE-122 CVE-2023-28527: IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206.
cvelistv5nvd
CVE-2023-28526MEDIUMCVSS 5.5v12.10v14.10+1 more2023-12-09
CVE-2023-28526 [MEDIUM] CWE-122 CVE-2023-28526: IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caus IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204.
cvelistv5nvd
CVE-2021-20515MEDIUMCVSS 6.7v14.10v14.12021-04-30
CVE-2021-20515 [MEDIUM] CWE-787 CVE-2021-20515: IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a denial of service condition. IBM X-Force ID: 198366.
cvelistv5nvd
CVE-2020-4799HIGHCVSS 7.8v14.102020-10-08
CVE-2020-4799 [HIGH] CWE-787 CVE-2020-4799: IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds write vulnerability. IBM X-Force ID: 189460.
cvelistv5nvd
CVE-2018-1796HIGHCVSS 7.8v12.102019-08-20
CVE-2018-1796 [HIGH] CVE-2018-1796: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user to load malicious libra IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user to load malicious libraries and gain root privileges. IBM X-Force ID: 149426.
nvd
CVE-2019-4253HIGHCVSS 7.8v12.102019-08-20
CVE-2019-4253 [HIGH] CVE-2019-4253: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious shared library and gain root access privileges. IBM X-Force ID: 159941.
nvd
CVE-2018-1631MEDIUMCVSS 6.7v12.12019-08-20
CVE-2018-1631 [MEDIUM] CWE-59 CVE-2018-1631: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID: 144431.
nvd
CVE-2018-1635MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1635 [MEDIUM] CWE-787 CVE-2018-1635: Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144439.
nvd
CVE-2018-1632MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1632 [MEDIUM] CWE-59 CVE-2018-1632: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432.
nvd
CVE-2018-1636MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1636 [MEDIUM] CWE-787 CVE-2018-1636: Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force ID: 144441.
nvd
CVE-2018-1630MEDIUMCVSS 6.7v12.12019-08-20
CVE-2018-1630 [MEDIUM] CWE-59 CVE-2018-1630: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430.
nvd
CVE-2018-1633MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1633 [MEDIUM] CWE-59 CVE-2018-1633: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434.
nvd
CVE-2018-1634MEDIUMCVSS 6.7v12.102019-08-20
CVE-2018-1634 [MEDIUM] CWE-59 CVE-2018-1634: IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force ID: 144437.
nvd
CVE-2017-1508MEDIUMCVSS 6.7v12.102017-09-13
CVE-2017-1508 [MEDIUM] CVE-2017-1508: IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620.
nvd
CVE-2017-1310MEDIUMCVSS 6.5v12.102017-06-29
CVE-2017-1310 [MEDIUM] CWE-119 CVE-2017-1310: IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that w IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system and cause the server to crash. IBM X-Force ID: 125569.
nvd