IBM Informix Dynamic Server
cpe:2.3:a:ibm:informix_dynamic_server:*:*:*:*:*:*:*
- 14.10
- ~12.10
A vulnerability exists in IBM Informix Dynamic Server versions 12.10 and 14.10, where an inadequate account lockout policy could enable remote attackers to brute force account credentials. The application fails to lock out users after multiple incorrect password attempts, allowing for repeated login attempts without restriction.
Exploitation of this vulnerability could lead to unauthorized access through successful credential brute forcing.
Users can upgrade to IBM Informix HQ versions 12.10.xC16W2, 14.10.xC11W1, or Informix HQ version 3.0.0 to address this vulnerability. These fixes are available on IBM Fix Central. Follow the instructions for database server upgrades in the Informix Servers documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.