Medium severity6.3NVD Advisory· Published Jun 28, 2023· Updated Jun 17, 2026
CVE-2023-27866
CVE-2023-27866
Description
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String. IBM X-Force ID: 249511.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:ibm:informix_jdbc_driver:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:ibm:informix_jdbc_driver:*:*:*:*:*:*:*:*range: >=4.50.0,<4.50.10
- cpe:2.3:a:ibm:informix_jdbc_driver:4.10:*:*:*:*:*:*:*
- (no CPE)range: 4.10, 4.50
Patches
Vulnerability mechanics
References
2- www.ibm.com/support/pages/node/7007615nvdPatchVendor Advisory
- exchange.xforce.ibmcloud.com/vulnerabilities/249511nvdVDB EntryVendor Advisory
News mentions
0No linked articles in our index yet.