First published: Tue Dec 19 2023(Updated: )
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 259116.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Informix JDBC | =4.10 | |
IBM Informix JDBC | =4.50 | |
<=4.10.x | ||
<=4.50.x |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35895 has been classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2023-35895, upgrade to a patched version of the IBM Informix JDBC Driver, specifically beyond versions 4.10 and 4.50.
Yes, CVE-2023-35895 can be exploited remotely via JNDI injection when using unchecked arguments.
CVE-2023-35895 affects IBM Informix JDBC Driver versions 4.10 and 4.50.
CVE-2023-35895 specifically affects the IBM Informix JDBC product.