First published: Tue Jun 27 2023(Updated: )
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix JDBC Driver | >=4.50.0<4.50.10 | |
IBM Informix JDBC Driver | =4.10 | |
<=4.10.x | ||
<=4.50.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27866 is classified as a high severity vulnerability due to its potential for remote code execution.
To fix CVE-2023-27866, validate and sanitize the LDAP URL in the Connect String before using it.
CVE-2023-27866 affects IBM Informix JDBC Driver versions 4.10 and 4.50.
CVE-2023-27866 is associated with a remote code execution attack via JNDI injection.
Detailed information about CVE-2023-27866 can be obtained from IBM's support resources.