IBM Informix Dynamic Server information disclosure
Published Jul 28, 2025
7.5
HIGHCVSS 3.1
EPSS 0.34%
Description
IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Affected products
-
Affected
- 12.10
- 14.10
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| IBM | Informix Dynamic Server | unaffected | Affected
|
- 12.10
- 14.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
A permanent fix for the vulnerability has been released in IBM Informix HQ, included with versions 12.10.xC16W2, 14.10.xC11W1, and also addressed in IBM Informix HQ version 3.0.0.
Fixes are available on IBM Fix Central - Select Fixes - Informix Server. Download the latest fix for your product and version to pick up the security patches.
Follow the instructions for Database server upgrades in the Informix Servers documentation.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54828 Advisory
- https://www.ibm.com/support/pages/node/7240777 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-54828 | Advisory | |
| https://www.ibm.com/support/pages/node/7240777 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data