CVE-2023-27869

MEDIUM

IBM Db2 10.5, 11.1, 11.5 - Authenticated Remote Code Execution via TraceFile Logger Injection

Title source: llm
STIX 2.1

Description

IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249517.

References (3)

Core 3
Core References
Patch, Vendor Advisory vendor-advisory
https://www.ibm.com/support/pages/node/7010029

Scores

CVSS v3 6.3
EPSS 0.0019
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (3)
ibm/db2 10.5.0.11
ibm/db2 11.1.4.7
ibm/db2 11.5
Published Jul 10, 2023
Tracked Since Feb 18, 2026