Back

HIGH

IBM Informix Dynamic Server information disclosure

Published Jul 28, 2025

Description

IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.

Affected products

Remediation

Vendor solution

A permanent fix for the vulnerability has been released in IBM Informix HQ, included with versions 12.10.xC16W2, 14.10.xC11W1, and also addressed in IBM Informix HQ version 3.0.0.

Fixes are available on IBM Fix Central - Select Fixes - Informix Server. Download the latest fix for your product and version to pick up the security patches.

Follow the instructions for Database server upgrades in the Informix Servers documentation.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner ibm
Published Jul 28, 2025
Updated Jul 28, 2025
Reserved Oct 14, 2024

CISA Vulnrichment

Updated Jul 28, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner ibm
Published Jul 28, 2025
Updated Jul 28, 2025

GitHub

No data