IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Fixes

Solution

A permanent fix for the vulnerability has been released in IBM Informix HQ, included with versions 12.10.xC16W2, 14.10.xC11W1, and also addressed in IBM Informix HQ version 3.0.0. Fixes are available on IBM Fix Central - Select Fixes - Informix Server. Download the latest fix for your product and version to pick up the security patches. Follow the instructions for Database server upgrades in the Informix Servers documentation.


Workaround

No workaround given by the vendor.

History

Mon, 28 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Jul 2025 15:45:00 +0000

Type Values Removed Values Added
Description IBM Informix Dynamic Server 12.10 and 14.10 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.
Title IBM Informix Dynamic Server information disclosure
First Time appeared Ibm
Ibm informix Dynamic Server
Weaknesses CWE-307
CPEs cpe:2.3:a:ibm:informix_dynamic_server:12.10:-:*:*:-:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm informix Dynamic Server
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2025-07-28T17:19:52.455Z

Reserved: 2024-10-14T12:05:13.492Z

Link: CVE-2024-49342

cve-icon Vulnrichment

Updated: 2025-07-28T17:19:42.319Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-28T16:15:24.220

Modified: 2025-08-06T17:13:27.220

Link: CVE-2024-49342

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.