CVE-2012-4857

critical
Published 2012-12-08 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.0

Description

Buffer overflow in IBM Informix 11.50 through 11.50.xC9W2 and 11.70 before 11.70.xC7 allows remote authenticated users to execute arbitrary code via a crafted SQL statement.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
ibm ibminformix_dynamic_server11.50
ibm ibminformix_dynamic_server11.50.xc1
ibm ibminformix_dynamic_server11.50.xc2
ibm ibminformix_dynamic_server11.50.xc3
ibm ibminformix_dynamic_server11.50.xc3w1
ibm ibminformix_dynamic_server11.50.xc4
ibm ibminformix_dynamic_server11.50.xc4w1
ibm ibminformix_dynamic_server11.50.xc5
ibm ibminformix_dynamic_server11.50.xc5w2
ibm ibminformix_dynamic_server11.50.xc5w3
ibm ibminformix_dynamic_server11.50.xc5w4
ibm ibminformix_dynamic_server11.50.xc6
ibm ibminformix_dynamic_server11.50.xc6w1
ibm ibminformix_dynamic_server11.50.xc6w2
ibm ibminformix_dynamic_server11.50.xc6w3
ibm ibminformix_dynamic_server11.50.xc6w4
ibm ibminformix_dynamic_server11.50.xc7
ibm ibminformix_dynamic_server11.50.xc7w1
ibm ibminformix_dynamic_server11.50.xc7w2
ibm ibminformix_dynamic_server11.50.xc7w3
ibm ibminformix_dynamic_server11.50.xc7w4
ibm ibminformix_dynamic_server11.50.xc8
ibm ibminformix_dynamic_server11.50.xc8w1
ibm ibminformix_dynamic_server11.50.xc8w2
ibm ibminformix_dynamic_server11.50.xc8w3
ibm ibminformix_dynamic_server11.50.xc8w4
ibm ibminformix_dynamic_server11.50.xc9
ibm ibminformix_dynamic_server11.70.xc1
ibm ibminformix_dynamic_server11.70.xc2
ibm ibminformix_dynamic_server11.70.xc3

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.