VulnerabilityModified
CVE-2023-27866
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String.
CRITICAL 9.8EPSS 1.03%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.03% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- ibm/informix jdbc driver
- Source
- psirt@us.ibm.com
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/249511VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7007615Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/249511VDB Entry, Vendor Advisory
- https://www.ibm.com/support/pages/node/7007615Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.