PT-2023-25367 · Ibm · Ibm Informix Jdbc Driver
Published
2023-12-20
·
Updated
2023-12-28
·
CVE-2023-35895
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM Informix JDBC Driver versions 4.10 through 4.50
Description
The issue allows for remote code execution via JNDI injection when an unchecked argument is passed to a certain API.
Recommendations
For versions 4.10 through 4.50, consider restricting access to the vulnerable API endpoint until a patch is available. As a temporary workaround, avoid passing unchecked arguments to the affected API.
Fix
OS Command Injection
Special Elements Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ibm Informix Jdbc Driver