| Publishing Date | 31.03.2026 |
|---|---|
| Last Update | 31.03.2026 |
| Tracking ID | IBA-2026-06 |
| CVE | See below |
CVE IDs of the affected library
- CVE‑2023‑2975
- CVE‑2023‑4807
- CVE‑2023‑5363
- CVE‑2023‑6129
- CVE‑2024‑2511
- CVE‑2024‑5535
- CVE‑2024‑9143
- CVE‑2025‑9232
- CVE‑2026‑22796
Summary
The implemented third‑party dependency libssl-3 contained several vulnerabilities. Multiple OpenSSL vulnerabilities could cause application crashes (DoS), data leakage, incorrect cryptographic processing, or unexpected behavior, due to issues in AES‑SIV, POLY1305, cipher initialization, TLS 1.3 session handling, elliptic‑curve parameter parsing, HTTP client parsing, and PKCS#7 signature validation.
No active exploitation of these vulnerabilities is known within the product.
Affected products
This applies to all iba products up to the versions listed below:
- ibaDatCoordinator v4.0.4
How do I know that I’m affected?
If you have installed any of the products listed above, you are affected.
Solution
With the following versions, the issue has been fixed:
- ibaDatCoordinator v4.0.5
Customer Actions
Please install the update as discript in the Solution.
Timeline
| 2026-02-26 | Noted by the Security Team |
| 2026-03-31 | Fix for the Problem in Version ibaDatCoordinator v4.0.5 |
