Impact
IBM Informix Dynamic Server in versions 12.10, 14.10 and 15.0 suffers from an input validation flaw that allows an attacker to send specially crafted messages to the Wire Listener, causing the server to execute arbitrary commands with the service account. The vulnerability is a path‑leading command injection (CWE‑78). Once exploited, the attacker gains system‑level control, which can lead to full compromise of the host, data exfiltration, or use as a pivot point in further attacks.
Affected Systems
The affected product is IBM Informix Dynamic Server, specifically the 12.10, 14.10, and 15.0 series. IBM has released a fix in the 14.10.xC13W13 and 15.0.1.13 releases, so only versions older than those are vulnerable.
Risk and Exploitability
The CVSS score of 7.3 reflects a high risk level, while the EPSS score is not available but indicates no publicly known exploit trend. The vulnerability is not listed in the CISA KEV catalog. Attackers can target the Wire Listener endpoint without authentication, meaning that anyone on the network path can trigger the exploit. Successful exploitation leads to execution of commands with the service account, essentially a remote code‑execution scenario.
OpenCVE Enrichment