7.3
CVE-2026-13476
- EPSS 0.55%
- Veröffentlicht 12.08.2026 20:58:16
- Zuletzt bearbeitet 18.08.2026 18:38:48
- CVE-Watchlists
- Unerledigt
IBM Informix Wire Listener Vulnerable to Unauthenticated Remote Code Execution
IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ibm ≫ Informix Dynamic Server Version >= 15.0 < 15.0.1.13
Canonical ≫ Ubuntu Linux Version-
Hp ≫ Hp-ux Version-
Ibm ≫ Aix Version-
Ibm ≫ Linux On Ibm Z Version-
Linux ≫ Linux Kernel Version-
Novell ≫ Suse Linux Version-
Oracle ≫ Solaris Version-
Redhat ≫ Desktop Version-
Hp ≫ Hp-ux Version-
Ibm ≫ Aix Version-
Ibm ≫ Linux On Ibm Z Version-
Linux ≫ Linux Kernel Version-
Novell ≫ Suse Linux Version-
Oracle ≫ Solaris Version-
Redhat ≫ Desktop Version-
Ibm ≫ Informix Dynamic Server Version12.10
Canonical ≫ Ubuntu Linux Version-
Hp ≫ Hp-ux Version-
Ibm ≫ Aix Version-
Ibm ≫ Linux On Ibm Z Version-
Linux ≫ Linux Kernel Version-
Novell ≫ Suse Linux Version-
Oracle ≫ Solaris Version-
Redhat ≫ Desktop Version-
Hp ≫ Hp-ux Version-
Ibm ≫ Aix Version-
Ibm ≫ Linux On Ibm Z Version-
Linux ≫ Linux Kernel Version-
Novell ≫ Suse Linux Version-
Oracle ≫ Solaris Version-
Redhat ≫ Desktop Version-
Ibm ≫ Informix Dynamic Server Version14.10
Canonical ≫ Ubuntu Linux Version-
Hp ≫ Hp-ux Version-
Ibm ≫ Aix Version-
Ibm ≫ Linux On Ibm Z Version-
Linux ≫ Linux Kernel Version-
Novell ≫ Suse Linux Version-
Oracle ≫ Solaris Version-
Redhat ≫ Desktop Version-
Hp ≫ Hp-ux Version-
Ibm ≫ Aix Version-
Ibm ≫ Linux On Ibm Z Version-
Linux ≫ Linux Kernel Version-
Novell ≫ Suse Linux Version-
Oracle ≫ Solaris Version-
Redhat ≫ Desktop Version-
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.432 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| IBM | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
https://www.ibm.com/support/pages/node/7282827