CVE-2023-27867: IBM Db2 code execution
IBM Db2 JDBC Driver could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Other sources
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-27867?
CVE-2023-27867 is a vulnerability in the IBM Db2 JDBC Driver that could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection.
Which versions of IBM Db2 are affected by CVE-2023-27867?
IBM Db2 versions 10.5.0.11, 11.1.4.7, and 11.5.x are affected by CVE-2023-27867.
What is the severity of CVE-2023-27867?
CVE-2023-27867 has a severity rating of 8.8, which is considered high.
How can a remote authenticated attacker exploit CVE-2023-27867?
A remote authenticated attacker can exploit CVE-2023-27867 by sending a specially crafted request using the property clientRerouteServerListJNDIName.
Are there any references for CVE-2023-27867?
Yes, here are some references for CVE-2023-27867: [link1](https://exchange.xforce.ibmcloud.com/vulnerabilities/249514), [link2](https://www.ibm.com/support/pages/node/7010029), [link3](https://security.netapp.com/advisory/ntap-20230803-0006/).