CVE-2023-27867
published 2023-07-10CVE-2023-27867: IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.63%
73.5th percentile
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | db2 | — | — |
| ibm | db2 | — | — |
| ibm | db2 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
ghsa·2026-06-11
CVE-2025-27511 [HIGH] CWE-502 GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
GeoServer DB2 DataStore Extension has a JNDI Vulnerability via Store Connection
## Summary
Administrator can perform JNDI attack through specially crafted DB2 jdbc url leading to Remote Code Execution (RCE).
## Impact
If GeoServer has DB2 extension installed, this vulnerability can lead to executing arbitrary code.
## Details
Authenticated users can access Vector Data Sources page to creating a new data store through db2 jdbc connection, performing JNDI attack due to unrestricted connection parameters, and then achieve RCE with deserialization of untrusted data.
### Remediation
This issue has been fixed in this release: https://github.com/geoserver/geoserver/releases/tag/2.27.0.
## References
* https://osgeo-org.atlassian.net/browse/GEOT-7725
* https://nvd.nist.gov/vuln/detail/cv
GHSA
GHSA-6rh4-jr4q-29gx: IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10
ghsa_unreviewed·2023-07-10
CVE-2023-27867 [HIGH] CWE-94 GHSA-6rh4-jr4q-29gx: IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://exchange.xforce.ibmcloud.com/vulnerabilities/249514https://security.netapp.com/advisory/ntap-20230803-0006/https://www.ibm.com/support/pages/node/7010029https://exchange.xforce.ibmcloud.com/vulnerabilities/249514https://security.netapp.com/advisory/ntap-20230803-0006/https://www.ibm.com/support/pages/node/7010029
2023-07-10
Published