CVE-2023-27868: IBM Db2 code execution
IBM Db2 JDBC Driver could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Other sources
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249516.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-27868?
CVE-2023-27868 is a vulnerability in the IBM Db2 JDBC Driver that could allow a remote authenticated attacker to execute arbitrary code on the system.
How does CVE-2023-27868 affect IBM Db2?
CVE-2023-27868 affects IBM Db2 versions 10.5.0.11, 11.1.4.7, and 11.5.x.
What is the severity of CVE-2023-27868?
The severity of CVE-2023-27868 is high with a CVSS score of 8.8.
How can a remote authenticated attacker exploit CVE-2023-27868?
A remote authenticated attacker can exploit CVE-2023-27868 by sending a specially crafted request using the named plugin classes.
Are there any references for CVE-2023-27868?
Yes, you can find more information about CVE-2023-27868 at the following references: [Reference 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/249516), [Reference 2](https://www.ibm.com/support/pages/node/7010029), [Reference 3](https://security.netapp.com/advisory/ntap-20230803-0006/)