CVE-2026-13361

8.8

IBM · Informix Dynamic Server

A stack-based buffer overflow in IBM Informix Dynamic Server allows remote, authenticated attackers to execute arbitrary code via an unchecked SQL interface length field.

Executive summary

A stack-based buffer overflow in IBM Informix Dynamic Server allows authenticated attackers to achieve remote code execution.

Vulnerability

This vulnerability (CWE-121) involves a stack-based buffer overflow triggered by an unchecked length field within the SQL interface. Exploitation requires low privileges (authenticated access) to the database server.

Business impact

An attacker successfully exploiting this vulnerability could execute arbitrary code with the privileges of the Informix service, leading to full system compromise. With a CVSS score of 8.8, this represents a critical risk to the security of the database server and any data hosted within it.

Remediation

Immediate Action: Upgrade to IBM Informix versions 14.10.xC13W13 or 15.0.1.14 as specified in the vendor security advisory.

Proactive Monitoring: Monitor database server logs for anomalous crashes or unexpected service restarts which may indicate failed exploitation attempts or memory corruption.

Compensating Controls: Restrict network access to the Informix SQL interface to trusted internal segments only, reducing the attack surface available to potential unauthorized users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing IBM Informix must treat this as a high-priority update. Promptly applying the vendor-provided patches is essential to prevent potential remote code execution and maintain the integrity of the database infrastructure.

More IBM CVEs