PT-2023-21383 · Ibm · Ibm Informix Jdbc Driver

Xu Yuanzhen

·

Published

2023-06-28

·

Updated

2023-07-06

·

CVE-2023-27866

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM Informix JDBC Driver versions 4.10 and 4.50
Description The issue allows for remote code execution via JNDI injection when the driver code or the application using the driver does not verify the supplied LDAP URL in the Connect String.
Recommendations For IBM Informix JDBC Driver versions 4.10 and 4.50, consider verifying the supplied LDAP URL in the Connect String to prevent JNDI injection attacks. As a temporary workaround, consider restricting the use of the Connect String or the LDAP URL until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-27866

Affected Products

Ibm Informix Jdbc Driver