ZeroHour

CVE-2023-27866

CVSS 3.1
9.8 critical
EPSS
1%p62
Published
()
Modified
Description

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.

Vendors
ibm
Products
informix jdbc driver
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.