Skip to main navigation Skip to main content Skip to page footer

Memory Corruption Vulnerability in External SQLite Dependency

Security Advisories IBA-2026-04

Grüner Hintergrund mit kreisförmigem digitalem Interface-Design.
Publishing Date 31.03.2026
Last Update 26.06.2026
Tracking IDIBA-2026-04
CVESee below
CVSS Base Score7.2
CVSS Vector CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/S:N/AU:N/R:U/V:D/RE:L/U:Green

CVE ID(s) of the affected library

  • CVE-2025-6965

Summary

The SQLite functionality used in the iba product relied on a third‑party component that contains a memory‑corruption flaw (CVE-2025-6965). The vulnerability occurs when aggregate terms exceed the number of available columns, which can lead to memory corruption within the application. There are no known cases of exploitation of this vulnerability.

Affected products

This applies to all iba products up to the versions listed below:

  • ibaHD-Server v3.5.2
  • ibaDatCoordinator v4.0.7
  • ibaAnalyzer v8.3.5

How do I know that I’m affected?

If you have installed any of the products listed above, you are affected.

Solution

With the following versions, the issue has been fixed:

  • ibaHD-Server v3.6.0
  • ibaDatCoordinator v4.1.0
  • ibaAnalyzer v8.4.0

Customer Actions

Please install the update as described in the solution.

Timeline

2026-02-26Noted by the Security Team.
2026-03-31Resolved in version ibaHD-Server v3.6.0.
2026-06-25Resolved in version ibaDatCoordinator v4.1.0.
2026-06-26Resolved in version ibaDatCoordinator v8.4.0
Zurück zur Übersicht

Was möchten Sie heute machen?

Mit der Auswahl des Landes wird meine Anfrage an die zuständige Landesniederlassung der iba AG für Vertrieb und Support weitergeleitet.Datenschutz­erklärung