IBM Informix Web DataBlade 4.12 unescapes user input even if an application has escaped it, which could allow remote attackers to execute SQL code in a web form even when the developer has attempted to escape it.
| Software | From | Fixed in |
|---|---|---|
| ibm / informix_web_datablade | 4.10 | 4.10.x |
| ibm / informix_web_datablade | 4.11 | 4.11.x |
| ibm / informix_web_datablade | 4.13 | 4.13.x |
| ibm / informix_web_datablade | 4.12 | 4.12.x |