Lucene search

K
cveIbmCVE-2023-27866
HistoryJun 28, 2023 - 4:15 p.m.

CVE-2023-27866

2023-06-2816:15:19
CWE-94
ibm
web.nvd.nist.gov
12
cve-2023-27866
ibm
informix
jdbc driver
remote code execution
jndi injection
ldap url
connect string
ibm x-force id
249511

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.005

Percentile

77.7%

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.

Affected configurations

Nvd
Vulners
Node
ibminformix_jdbc_driverRange4.50.04.50.10
OR
ibminformix_jdbc_driverMatch4.10
VendorProductVersionCPE
ibminformix_jdbc_driver*cpe:2.3:a:ibm:informix_jdbc_driver:*:*:*:*:*:*:*:*
ibminformix_jdbc_driver4.10cpe:2.3:a:ibm:informix_jdbc_driver:4.10:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Informix JDBC",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "4.10, 4.50"
      }
    ]
  }
]

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.005

Percentile

77.7%

Related for CVE-2023-27866