Lucene search

K
cvelistIbmCVELIST:CVE-2023-27866
HistoryJun 28, 2023 - 3:41 p.m.

CVE-2023-27866 IBM Informix JDBC code execution

2023-06-2815:41:11
CWE-94
ibm
www.cve.org
5
ibm
informix
jdbc
code execution
vulnerability
remote
jndi injection
ldap
url
x-force id 249511

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

9.5

Confidence

High

EPSS

0.005

Percentile

77.7%

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Informix JDBC",
    "vendor": "IBM",
    "versions": [
      {
        "status": "affected",
        "version": "4.10, 4.50"
      }
    ]
  }
]

CVSS3

6.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

AI Score

9.5

Confidence

High

EPSS

0.005

Percentile

77.7%

Related for CVELIST:CVE-2023-27866