Lucene search

K
nvd[email protected]NVD:CVE-2023-27866
HistoryJun 28, 2023 - 4:15 p.m.

CVE-2023-27866

2023-06-2816:15:19
CWE-94
web.nvd.nist.gov
3
ibm
informix jdbc
remote code execution
jndi injection
ldap url
security vulnerability

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.005

Percentile

77.7%

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.

Affected configurations

Nvd
Node
ibminformix_jdbc_driverRange4.50.04.50.10
OR
ibminformix_jdbc_driverMatch4.10
VendorProductVersionCPE
ibminformix_jdbc_driver*cpe:2.3:a:ibm:informix_jdbc_driver:*:*:*:*:*:*:*:*
ibminformix_jdbc_driver4.10cpe:2.3:a:ibm:informix_jdbc_driver:4.10:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.005

Percentile

77.7%

Related for NVD:CVE-2023-27866