Description
IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.
Published: 2025-12-02
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Remediation/Fixes Impact is limited to Informix Server on Windows. No exploitation has been observed or is possible on non‑Windows platforms. Update to IBM Informix Dynamic Server 14.10.xC11W1. Fix is available on IBM Fix Central - Select Fixes - Informix Server . Follow the instructions for Database server upgrades in the Informix Servers documentation Follow the instructions to install or upgrade Informix in the What's new and changed in Informix in the IBM Cloud Pak for Data documentation.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Dec 2025 17:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:-:*:*:*

Tue, 02 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 02:30:00 +0000

Type Values Removed Values Added
Description IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.
Title IBM Informix Dynamic Server Authentication Bypass
First Time appeared Ibm
Ibm informix Dynamic Server
Weaknesses CWE-309
CPEs cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm informix Dynamic Server
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Informix Dynamic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-02-26T16:57:48.171Z

Reserved: 2024-09-03T13:50:43.964Z

Link: CVE-2024-45675

cve-icon Vulnrichment

Updated: 2025-12-02T16:51:41.162Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T03:16:14.587

Modified: 2025-12-03T17:26:23.860

Link: CVE-2024-45675

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses