CVE-2023-27869: IBM Db2 code execution
IBM Db2 JDBC Driver could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Other sources
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249517.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-27869?
CVE-2023-27869 is a vulnerability in the IBM Db2 JDBC Driver that could allow a remote authenticated attacker to execute arbitrary code on the system.
Which versions of IBM Db2 are affected by CVE-2023-27869?
IBM Db2 versions 10.5.0.11, 11.1.4.7, and 11.5.x are affected by CVE-2023-27869.
How severe is CVE-2023-27869?
CVE-2023-27869 has a severity rating of 8.8 (high).
What is the Common Weakness Enumeration (CWE) for CVE-2023-27869?
The CWE for CVE-2023-27869 is CWE-94 (Improper Control of Generation of Code)
Where can I find more information about CVE-2023-27869?
You can find more information about CVE-2023-27869 at the following references: [Link 1](https://exchange.xforce.ibmcloud.com/vulnerabilities/249517), [Link 2](https://www.ibm.com/support/pages/node/7010029), [Link 3](https://security.netapp.com/advisory/ntap-20230803-0006/)