{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2024-45675","assignerOrgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","state":"PUBLISHED","assignerShortName":"ibm","dateReserved":"2024-09-03T13:50:43.964Z","datePublished":"2025-12-02T02:00:26.554Z","dateUpdated":"2026-02-26T16:57:48.171Z"},"containers":{"cna":{"affected":[{"cpes":["cpe:2.3:a:ibm:informix_dynamic_server:14.10:*:*:*:*:*:*:*"],"product":"Informix Dynamic Server","vendor":"IBM","versions":[{"status":"affected","version":"14.10"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password.</p>"}],"value":"IBM Informix Dynamic Server 14.10 could allow a local user on the system to log into the Informix server as administrator without a password."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":8.4,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-309","description":"CWE-309 Use of Password System for Primary Authentication","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9a959283-ebb5-44b6-b705-dcc2bbced522","shortName":"ibm","dateUpdated":"2025-12-02T02:00:26.554Z"},"references":[{"tags":["vendor-advisory","patch"],"url":"https://www.ibm.com/support/pages/node/7252704"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Remediation/Fixes Impact is limited to Informix Server on Windows. No exploitation has been observed or is possible on non‑Windows platforms. Update to IBM Informix Dynamic Server 14.10.xC11W1. Fix is available on IBM Fix Central - Select Fixes - Informix Server . Follow the instructions for Database server upgrades in the Informix Servers documentation Follow the instructions to install or upgrade Informix in the What's new and changed in Informix in the IBM Cloud Pak for Data documentation.</p>"}],"value":"Remediation/Fixes Impact is limited to Informix Server on Windows. No exploitation has been observed or is possible on non‑Windows platforms. Update to IBM Informix Dynamic Server 14.10.xC11W1. Fix is available on IBM Fix Central - Select Fixes - Informix Server . Follow the instructions for Database server upgrades in the Informix Servers documentation Follow the instructions to install or upgrade Informix in the What's new and changed in Informix in the IBM Cloud Pak for Data documentation."}],"title":"IBM Informix Dynamic Server Authentication Bypass","x_generator":{"engine":"ibm-cvegen"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"id":"CVE-2024-45675","role":"CISA Coordinator","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"version":"2.0.3","timestamp":"2025-12-03T04:55:39.716301Z"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-02-26T16:57:48.171Z"}}]}}