← Vulnerability feed

Vulnerability record · CVE-2017-1092 · published 22 May 2017

CVE-2017-1092: IBM Informix Open Admin Tool unauthenticated remote code execution

Ibm · Informix Open Admin Tool

IBM Informix Open Admin Tool versions 11.5, 11.7 and 12.1 on Windows allow an unauthorized user to execute arbitrary code with system administrator privileges. The flaw is remotely reachable with no authentication or user interaction, and the vendor has published a patch. Because it yields full administrative code execution on the host, it is a severe risk for any exposed deployment.

9.8 CVSS 3.0 Critical EPSS 76% · top 0.5%
9.8CVSS 3.0 base score, v2 10.0
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

IBM Informix Open Admin Tool 11.5, 11.7, and 12.1 could allow an unauthorized user to execute arbitrary code as system admin on Windows servers. IBM X-Force ID: 120390.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityUnauthenticated network-reachable code execution as Windows system administrator with public exploit code and very high EPSS makes this an urgent patching priority.

What it is

IBM Informix Open Admin Tool versions 11.5, 11.7 and 12.1 on Windows allow an unauthorized user to execute arbitrary code with system administrator privileges. The flaw is remotely reachable with no authentication or user interaction, and the vendor has published a patch. Because it yields full administrative code execution on the host, it is a severe risk for any exposed deployment.

Impact

An unauthenticated attacker gains arbitrary code execution as a Windows system administrator, giving full control of the affected server and any data or services it hosts.

Attack surface

Reached over the network via the Open Admin Tool interface, per the CVSS vector AV:N/AC:L/PR:N/UI:N, meaning no credentials and no user interaction are required. The record does not specify the exact vulnerable endpoint or component.

Exploitation

CVE-2017-1092 is not listed in CISA KEV, but EPSS is very high at 0.758 (99.5th percentile) and two public Exploit-DB entries exist, indicating public exploit code is available.

What to do

  • Apply the IBM patch referenced in the vendor advisory swg22002897 for the affected Open Admin Tool versions.
  • Upgrade to a supported Open Admin Tool release if 11.5, 11.7 or 12.1 is still in use.
  • Restrict network access to the Open Admin Tool interface to trusted management hosts only; do not expose it to the internet.
  • Run the Open Admin Tool service under a least-privilege account rather than a Windows system administrator context.
  • Monitor for and remove any unauthorized administrative accounts or services created after suspected exposure.

Detection

  • Review Open Admin Tool and web server logs for unexpected requests or command execution patterns from untrusted source IPs.
  • Alert on new Windows services, scheduled tasks or local administrator accounts created on hosts running Open Admin Tool.
  • Monitor process creation on Informix/Open Admin Tool servers for child processes spawned by the service account.
  • Audit network exposure of the Open Admin Tool port and flag any external reachability.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-1092 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2017-1092), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.