CVE-2024-49342

7.5

IBM · Informix Dynamic Server

IBM Informix Dynamic Server 12.10 and 14.10 contain an inadequate account lockout mechanism, potentially allowing remote attackers to perform brute force attacks to compromise credentials.

Executive summary

A vulnerability in IBM Informix Dynamic Server allows remote attackers to conduct brute force attacks due to insufficient account lockout protections, posing a significant risk to credential security.

Vulnerability

This vulnerability is categorized as an improper restriction of excessive authentication attempts (CWE-307). It allows an unauthenticated, remote attacker to repeatedly attempt logins without triggering account lockout procedures.

Business impact

Successful exploitation of this flaw can lead to unauthorized access to sensitive database environments by guessing valid user credentials. Given the CVSS score of 7.5, this high-severity issue necessitates immediate attention to prevent potential data breaches, unauthorized modifications, or prolonged operational disruption resulting from compromised administrative accounts.

Remediation

Immediate Action: Update IBM Informix Dynamic Server to versions 12.10.xC16W2 or 14.10.xC11W1, or update the Informix HQ component to version 3.0.0.

Proactive Monitoring: Review database authentication logs for high volumes of failed login attempts originating from single or multiple IP addresses that deviate from established user behavior baselines.

Compensating Controls: Deploy or tune network-level firewalls and intrusion prevention systems to detect and block repetitive authentication traffic patterns directed at the database server.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The risk posed by this vulnerability is significant due to the potential for automated credential harvesting. Administrators must prioritize the application of the vendor-supplied patches to ensure the account lockout mechanism is correctly enforced. Failure to remediate this issue leaves database instances susceptible to unauthorized access and potential data exfiltration.

More IBM CVEs

Sources