| Publishing Date | 2026-03-31 |
|---|---|
| Last Update | 2026-06-26 |
| Tracking ID | IBA-2026-04 |
| CVE | See below |
| CVSS Base Score | 7.2 |
| CVSS Vector | CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/S:N/AU:N/R:U/V:D/RE:L/U:Green |
CVE ID(s) of the affected library
- CVE-2025-6965
Summary
The SQLite functionality used in the iba product relied on a third‑party component that contains a memory‑corruption flaw (CVE-2025-6965). The vulnerability occurs when aggregate terms exceed the number of available columns, which can lead to memory corruption within the application. There are no known cases of exploitation of this vulnerability.
Affected products
This applies to all iba products up to the versions listed below:
- ibaHD-Server v3.5.2
- ibaDatCoordinator v4.0.7
- ibaAnalyzer v8.3.5
How do I know that I’m affected?
If you have installed any of the products listed above, you are affected.
Solution
With the following versions, the issue has been fixed:
- ibaHD-Server v3.6.0
- ibaDatCoordinator v4.1.0
- ibaAnalyzer v8.4.0
Customer Actions
Please install the update as described in the solution.
Timeline
| 2026-02-26 | Noted by the Security Team. |
| 2026-03-31 | Resolved in version ibaHD-Server v3.6.0. |
| 2026-06-25 | Resolved in version ibaDatCoordinator v4.1.0. |
| 2026-06-26 | Resolved in version ibaDatCoordinator v8.4.0 |
