CVE-2023-27868 – IBM Db2 code execution
https://notcve.org/view.php?id=CVE-2023-27868
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked class instantiation when providing plugin classes. By sending a specially crafted request using the named pluginClassName class, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249516. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249516 https://security.netapp.com/advisory/ntap-20230803-0006 https://www.ibm.com/support/pages/node/7010029 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-27867 – IBM Db2 code execution
https://notcve.org/view.php?id=CVE-2023-27867
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code via JNDI Injection. By sending a specially crafted request using the property clientRerouteServerListJNDIName, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249514. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249514 https://security.netapp.com/advisory/ntap-20230803-0006 https://www.ibm.com/support/pages/node/7010029 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-27869 – IBM Db2 code execution
https://notcve.org/view.php?id=CVE-2023-27869
IBM Db2 JDBC Driver for Db2 for Linux, UNIX and Windows 10.5, 11.1, and 11.5 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unchecked logger injection. By sending a specially crafted request using the named traceFile property, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 249517. • https://exchange.xforce.ibmcloud.com/vulnerabilities/249517 https://security.netapp.com/advisory/ntap-20230803-0006 https://www.ibm.com/support/pages/node/7010029 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2023-30449 – IBM Db2 denial of service
https://notcve.org/view.php?id=CVE-2023-30449
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query. IBM X-Force ID: 253439. • https://exchange.xforce.ibmcloud.com/vulnerabilities/253439 https://security.netapp.com/advisory/ntap-20230731-0007 https://www.ibm.com/support/pages/node/7010557 • CWE-20: Improper Input Validation •
CVE-2023-30445 – IBM Db2 denial of service
https://notcve.org/view.php?id=CVE-2023-30445
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query on certain tables. IBM X-Force ID: 253357. • https://exchange.xforce.ibmcloud.com/vulnerabilities/253357 https://security.netapp.com/advisory/ntap-20230731-0007 https://www.ibm.com/support/pages/node/7010557 • CWE-20: Improper Input Validation •