IBM
IBM Informix Dynamic Server: vulnerabilidades y CVE
IBM Informix Dynamic Server tiene 53 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE53
Últimos 12 meses4
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-13476 | Alta (7.3) | 0.43% | — | 12 ago 2026 | IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input. |
| CVE-2026-13367 | Alta (7.8) | 0.14% | — | 12 ago 2026 | IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. |
| CVE-2026-13361 | Alta (8.8) | 0.49% | — | 12 ago 2026 | IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. |
| CVE-2024-45675 | Alta (7.8) | 0.11% | — | 2 dic 2025 | IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password. |
| CVE-2024-49343 | Media (5.4) | 0.20% | — | 28 jul 2025 | IBM Informix Dynamic Server 12.10 and 14.10 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security… |
| CVE-2024-49342 | Alta (7.5) | 0.34% | — | 28 jul 2025 | IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. |
| CVE-2025-1991 | Alta (7.5) | 0.44% | — | 28 jun 2025 | IBM Informix Dynamic Server 12.10,14.10, and15.0 could allow a remote attacker to cause a denial of service due to an integer underflow when processing packets. |
| CVE-2023-28527 | Media (5.5) | 0.23% | — | 9 dic 2023 | IBM Informix Dynamic Server 12.10 and 14.10 cdr is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251206. |
| CVE-2023-28526 | Media (5.5) | 0.23% | — | 9 dic 2023 | IBM Informix Dynamic Server 12.10 and 14.10 archecker is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow a local user to cause a segmentation fault. IBM X-Force ID: 251204. |
| CVE-2023-28523 | Alta (7.8) | 0.29% | — | 9 dic 2023 | IBM Informix Dynamic Server 12.10 and 14.10 onsmsync is vulnerable to a heap buffer overflow, caused by improper bounds checking which could allow an attacker to execute arbitrary code. IBM X-Force ID: 250753. |
| CVE-2021-20515 | Media (6.7) | 0.32% | — | 30 abr 2021 | IBM Informix Dynamic Server 14.10 is vulnerable to a stack based buffer overflow, caused by improper bounds checking. A local privileged user could overflow a buffer and execute arbitrary code on the system or cause a… |
| CVE-2020-4799 | Alta (7.8) | 0.37% | — | 8 oct 2020 | IBM Informix spatial 14.10 could allow a local user to execute commands as a privileged user due to an out of bounds write vulnerability. IBM X-Force ID: 189460. |
| CVE-2019-4253 | Alta (7.8) | 0.42% | — | 20 ago 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local privileged Informix user to load a malicious shared library and gain root access privileges. IBM X-Force ID: 159941. |
| CVE-2018-1796 | Alta (7.8) | 0.36% | — | 20 ago 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user to load malicious libraries and gain root privileges. IBM X-Force ID: 149426. |
| CVE-2018-1636 | Media (6.7) | 0.44% | — | 20 ago 2019 | Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force… |
| CVE-2018-1635 | Media (6.7) | 0.44% | — | 20 ago 2019 | Stack-based buffer overflow in oninit in IBM Informix Dynamic Server Enterprise Edition 12.1 allows an authenticated user to execute predefined code with root privileges, such as escalating to a root shell. IBM X-Force… |
| CVE-2018-1634 | Media (6.7) | 0.42% | — | 20 ago 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in infos.DBSERVERNAME. IBM X-Force… |
| CVE-2018-1633 | Media (6.7) | 0.42% | — | 20 ago 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onsrvapd. IBM X-Force ID: 144434. |
| CVE-2018-1632 | Media (6.7) | 0.42% | — | 20 ago 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in .infxdirs. IBM X-Force ID: 144432. |
| CVE-2018-1631 | Media (6.7) | 0.42% | — | 20 ago 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in oninit mongohash. IBM X-Force ID:… |
| CVE-2018-1630 | Media (6.7) | 0.42% | — | 20 ago 2019 | IBM Informix Dynamic Server Enterprise Edition 12.1 could allow a local user logged in with database administrator user to gain root privileges through a symbolic link vulnerability in onmode. IBM X-Force ID: 144430. |
| CVE-2017-1508 | Media (6.7) | 0.33% | — | 13 sept 2017 | IBM Informix Dynamic Server 12.1 could allow a local user logged in with database administrator user to gain root privileges. IBM X-Force ID: 129620. |
| CVE-2017-1310 | Media (6.5) | 1.7% | — | 29 jun 2017 | IBM Informix Dynamic Server 12.1 could allow an authenticated user to cause a buffer overflow that would write large assertion fail files to the server. Done enough times, this could use large parts of the file system… |
| CVE-2016-0226 | Alta (7.8) | 0.38% | — | 28 mar 2016 | The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain… |
| CVE-2012-4857 | Alta (9) | 4.6% | — | 8 dic 2012 | Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement. |
| CVE-2012-3334 | Alta (9) | 3.7% | — | 25 sept 2012 | Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 11.50 before 11.50.xC9W2 and 11.70 before 11.70.xC5 allows remote authenticated users to execute arbitrary code via crafted arguments in a SET COLLATION… |
| CVE-2011-1033 | Alta (9.3) | 4.8% | — | 15 feb 2011 | Stack-based buffer overflow in oninit in IBM Informix Dynamic Server (IDS) 11.50 allows remote attackers to execute arbitrary code via crafted arguments in the USELASTCOMMITTED session environment option in a SQL SET… |
| CVE-2010-4070 | Alta (10) | 5.1% | — | 25 oct 2010 | Integer overflow in librpc.dll in portmap.exe (aka the ISM Portmapper service) in ISM before 2.20.TC1.117 in IBM Informix Dynamic Server (IDS) 7.x before 7.31.xD11, 9.x before 9.40.xC10, 10.00 before 10.00.xC8, and… |
| CVE-2010-4069 | Alta (8.5) | 3.9% | — | 25 oct 2010 | Stack-based buffer overflow in IBM Informix Dynamic Server (IDS) 7.x through 7.31, 9.x through 9.40, 10.00 before 10.00.xC10, 11.10 before 11.10.xC3, and 11.50 before 11.50.xC3 allows remote authenticated users to… |
| CVE-2010-4053 | Alta (9) | 4.6% | — | 23 oct 2010 | Stack-based buffer overflow in an unspecified logging function in oninit.exe in IBM Informix Dynamic Server (IDS) 11.10 before 11.10.xC2W2 and 11.50 before 11.50.xC1 allows remote authenticated users to execute… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de IBM
AIX · 551Websphere Application Server · 519DB2 · 355Vios · 237Sterling B2B Integrator · 205I · 203Rational Quality Manager · 202Qradar Security Information AND Event Manager · 192Infosphere Information Server · 189Maximo Asset Management · 182Rational Doors Next Generation · 153Rational Team Concert · 142