CVE Published: 08/07/2023 |
CVE Updated: 23/10/2024 |
CVE Year: 2023 Source: ibm |
Vendor: IBM |
Product: Db2 for Linux, UNIX and Windows Status : PUBLISHED
CVE-2023-27867 Description
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514.
Metrics
CVSS Version: 3.1 |
Base Score: 6.3 MEDIUM Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L