| Publishing Date | 2025-11-13 |
|---|---|
| Last Update | 2026-01-29 |
| Tracking ID | IBA-2025-04 |
| CVE | CVE-2025-14988 |
| CVSS Base Score | 10 |
| CVSS Vector | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Summary
A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain conditions. This may impact the confidentiality, integrity, or availability of the system.
While there is no evidence of active exploitation, due to the potential severity, we strongly recommend applying the latest update as soon as possible.
Affected products
This applies to all iba products up to the versions listed below:
- ibaPDA v8.12.0
How do I know that I’m affected?
If you have installed any of the products listed above you are affected.
Mitigation
Steps for ibaPDA if Installing the Update Is Not Possible
- Enable User Management:
To activate user management, go to the User Management settings (found under the Configure option). Set a password for the admin user to enable user management. - Configure Server Access:
To configure, open Server Access Manager (found under Configure in the ibaPDA Client). Set the configuration so that, for example, only 127.0.0.1 (localhost) or specific system IP addresses that are allowed to communicate with ibaPDA can connect to the ibaPDA Server. (In this example, only connections from localhost are permitted to access ibaPDA.) - Restrict Connections to Localhost (if ibaPDA is only accessed from the system where it runs)
- Go to I/O Manager → General and deactivate the option “Automatically open necessary ports in Windows Firewall.” (If this option remains active, after a restart of ibaPDA or a restart for data acquisition, the firewall will be reconfigured automatically.)
- Then go to Advanced Windows Firewall settings and delete or deactivate all incoming rules for the ibaPDA Client and Server.
- Create manual firewall rules for the connection you use for ibaPDA and verify that you have the correct ports configured. Help regarding which ports the ibaPDA Service uses can be found in the iba Help Center.
- Imported: After the change, verify that all ibaPDA services are working as expected and that the data acquisition is functioning correctly.
Solution
Please update to the version listed below or a higher one.
- ibaPDA v8.12.1
Customer actions
Please install the update as described in the solution.
Timeline
| 2025-10-31 | Noted by the Security Team |
| 2025-11-13 | Fix for the problem in ibaPDA v8.12.1 |
