IBM Informix JDBC code execution
CVE-2023-35895

6.3MEDIUM

Key Information:

Vendor
IBM
Vendor
CVE Published:
20 December 2023

Summary

IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a certain API. IBM X-Force ID: 259116.

Affected Version(s)

Informix JDBC 4.10, 4.50

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.