Description
IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
Published: 2026-08-12
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the IBM Informix oninit sq_sgkprepare routine, where an unchecked length field in the SQL interface handler can overflow a stack buffer. Based on the description, it is inferred that the attacker must supply crafted SQL over the network to trigger the overflow. Exploitation allows an attacker to inject crafted SQL that overflows the buffer, giving the attacker control over the execution flow and the ability to run arbitrary code with the privileges of the database server process. This yields full confidentiality, integrity, and availability compromise of the affected server.

Affected Systems

IBM Informix Dynamic Server is affected, including versions 12.10.x, 14.10.0, 14.10, 15.0.0, and 15.0. All listed product lines are vulnerable until the vendor’s fix is applied. The vendor states the issue is resolved in Informix 14.10.xC13W13 and 15.0.1.14.

Risk and Exploitability

Based on the description, the likely attack vector is an attacker sending crafted SQL over the network to the Informix server, targeting the SQL interface handler. The CVSS score of 8.8 classifies the flaw as high severity, and while an EPSS score is not available, the lack of any known exploitation information in KEV suggests the vulnerability is not publicly known to be exploited yet. However, the nature of the vulnerability—a stack-based buffer overflow triggered by remote input—means a motivated adversary could craft a malicious payload over the network, exploiting the vulnerability before a patch is applied. The risk remains high until the specified fixed versions are deployed or until mitigation measures are enacted.

Generated by OpenCVE AI on August 12, 2026 at 22:35 UTC.

Remediation

Vendor Solution

The issue has been fixed in IBM Informix versions 14.10.xC13W13 and 15.0.1.14. Fixes are available on IBM Fix Central - Select Fixes - Informix Server. Follow the instructions for Database server upgrades in the Informix Servers documentation.


OpenCVE Recommended Actions

  • Apply the IBM Informix updates to version 14.10.xC13W13 or 15.0.1.14 as provided by IBM Fix Central
  • Follow IBM’s Informix Server documentation for database server upgrades, ensuring all prerequisites and prerequisites for the patch are met
  • If an immediate upgrade is not feasible, restrict network exposure to the Informix port and monitor server logs for anomalous SQL interface activity to detect potential exploitation attempts

Generated by OpenCVE AI on August 12, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:12.10:*:*:*:*:*:*:*

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Description IBM Informix Dynamic Server 14.10, 12.10.x, and 15.0 IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field. IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.

Wed, 12 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description IBM Informix Dynamic Server 14.10, 12.10.x, and 15.0 IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.
Title IBM Informix Server Vulnerability in SQL Interface Handler Could Allow Remote Code Execution
First Time appeared Ibm
Ibm informix Dynamic Server
Weaknesses CWE-121
CPEs cpe:2.3:a:ibm:informix_dynamic_server:12.10.x:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:14.10.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:15.0.0:*:*:*:*:*:*:*
cpe:2.3:a:ibm:informix_dynamic_server:15.0:*:*:*:*:*:*:*
Vendors & Products Ibm
Ibm informix Dynamic Server
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Ibm Informix Dynamic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: ibm

Published:

Updated: 2026-08-13T13:19:37.711Z

Reserved: 2026-06-25T18:43:01.237Z

Link: CVE-2026-13361

cve-icon Vulnrichment

Updated: 2026-08-13T13:19:32.006Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T20:17:34.857

Modified: 2026-08-18T18:37:14.397

Link: CVE-2026-13361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:45:10Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow