| Publishing Date | 31.03.2026 |
|---|---|
| Last Update | 31.03.2026 |
| Tracking ID | IBA-2026-05 |
| CVE | See below |
CVE IDs of the affected library
- CVE-2023-38546
- CVE-2023-38545
- CVE-2024-7264
- CVE-2025-14017
Summary
The implemented third‑party dependency libcurl contained several vulnerabilities. The resolved issues affected the processing of proxy handshakes, cookie duplication, ASN.1 certificate data parsing, and the handling of TLS options in multi‑threaded environments. The associated risks ranged from application crashes to data leakage and potential security bypasses. Updating to the latest library versions fully mitigates these issues.
No instances of active exploitation of these vulnerabilities within the product are known.
Affected products
This applies to all iba products up to the versions listed below:
- ibaDatCoordinator v4.0.4
How do I know that I’m affected?
If you have installed any of the products listed above, you are affected.
Solution
With the following versions, the issue has been fixed:
- ibaDatCoordinator v4.0.5
Customer Actions
Please install the update as discript in the Soloution
Timeline
| 2026-02-26 | Noted by the Security Team |
| 2026-03-31 | Fix for the Problem in Version ibaDatCoordinator v4.0.5 |
