PT-2023-21776 · Ibm · Ibm Informix Dynamic Server

Published

2023-12-08

·

Updated

2023-12-12

·

CVE-2023-28523

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Informix Dynamic Server versions 12.10 and 14.10
Description The issue is caused by improper bounds checking, leading to a heap buffer overflow. This could allow an attacker to execute arbitrary code.
Recommendations For IBM Informix Dynamic Server versions 12.10 and 14.10, consider disabling the onsmsync feature until a patch is available to prevent potential exploitation.

Fix

Memory Corruption

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-28523

Affected Products

Ibm Informix Dynamic Server