CVE-2004-2131

IBM Informix Dynamic Server <9.40.xC3 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2004-2131. PoCs published by pask.

AI-analyzed exploit summary This exploit targets a local stack-based buffer overflow in the ontape binary of IBM Informix Dynamic Server 9.40. It leverages an unchecked ONCONFIG environment variable to overwrite the stack and execute arbitrary shellcode, leading to privilege escalation from the informix user to root.

Description

Stack-based buffer overflow in ontape for IBM Informix Dynamic Server (IDS) 9.40.xC3 and earlier allows local users, with DSA privileges, to execute arbitrary code via a long ONCONFIG environment variable.

Exploits (2)

exploitdb WORKING POC VERIFIED
by pask · clocalunix
https://www.exploit-db.com/exploits/23610

This exploit targets a local stack-based buffer overflow in the ontape binary of IBM Informix Dynamic Server 9.40. It leverages an unchecked ONCONFIG environment variable to overwrite the stack and execute arbitrary shellcode, leading to privilege escalation from the informix user to root.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: IBM Informix Dynamic Server 9.40
Auth required
Prerequisites: Local access to the system · Informix user privileges · Presence of the vulnerable ontape binary
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by pask · bashlocalunix
https://www.exploit-db.com/exploits/23609

This exploit targets a predictable temporary file vulnerability in IBM Informix Dynamic Server's onedcu binary. It creates a symbolic link to a cron file, which is then overwritten to add a privileged user, achieving local privilege escalation.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: IBM Informix Dynamic Server 9.40 and Extended Parallel Server
No auth needed
Prerequisites: Local access to the system · Presence of vulnerable IBM Informix binaries · Write permissions in the target directory
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/3759
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9512
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/14970
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/10737/
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=107539878804074&w=2
Exploit, Patch, Vendor Advisory x_refsource_confirm
http://www-1.ibm.com/support/docview.wss?uid=swg21153336

Scores

EPSS 0.0143
EPSS Percentile 69.5%

Details

Status published
Products (3)
ibm/informix_dynamic_server 9.40.uc1
ibm/informix_dynamic_server 9.40.uc2
ibm/informix_extended_parallel_server 8.40_uc1
Published Jan 27, 2004
Tracked Since Feb 18, 2026