Vulnerability Details CVE-2023-27866
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.4%
CVSS Severity
CVSS v3 Score 6.3
Products affected by CVE-2023-27866
-
cpe:2.3:a:ibm:informix_jdbc_driver:*
-
cpe:2.3:a:ibm:informix_jdbc_driver:4.10