Lucene search

K
ibmIBMDA83455908E4D9CD54178057885C06975C6754D3776949CDE7E241DD630C92FF
HistoryAug 21, 2023 - 9:47 p.m.

Security Bulletin: IBM Informix JDBC Driver Is Vulnerable to Remote Code Execution (CVE-2023-27866)

2023-08-2121:47:15
www.ibm.com
31
ibm informix jdbc
remote code execution
vulnerability
jndi injection
connect string
cvss base score
cvss vector
affected products
fix central
informix jdbc 4.50.10
informix jdbc.4.10.jc16
ibm resources

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.7%

Summary

IBM Informix JDBC Driver is susceptible to remote code execution attack. This vulnerability is addressed.

Vulnerability Details

CVEID:CVE-2023-27866
**DESCRIPTION:**IBM Informix JDBC Driver is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String.
CVSS Base score: 6.3
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/249511 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)

Affected Products and Versions

Affected Product(s) Version(s)
Informix JDBC 4.10.x
Informix JDBC 4.50.x

Remediation/Fixes

Customers running any vulnerable fixpack level of an affected Program can download a fix from Fix Central.

  • Update to Informix JDBC 4.50.10
  • Update to Informix JDBC.4.10.JC16

Visit the following URL -

https://www.ibm.com/resources/mrs/assets?source=ifxids

Workarounds and Mitigations

None.

Affected configurations

Vulners
Node
ibminformix_jdbcMatch4.10.
OR
ibminformix_jdbcMatch4.50.
OR
ibminformix_jdbcMatch4.50
VendorProductVersionCPE
ibminformix_jdbc4.10.cpe:2.3:a:ibm:informix_jdbc:4.10.:*:*:*:*:*:*:*
ibminformix_jdbc4.50.cpe:2.3:a:ibm:informix_jdbc:4.50.:*:*:*:*:*:*:*
ibminformix_jdbc4.50cpe:2.3:a:ibm:informix_jdbc:4.50:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.005

Percentile

77.7%

Related for DA83455908E4D9CD54178057885C06975C6754D3776949CDE7E241DD630C92FF