CVE-2023-27859: IBM Db2 code execution
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.
Other sources
IBM Db2 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-27859?
CVE-2023-27859 has been rated as a critical vulnerability due to its potential to allow arbitrary code execution by remote users.
How do I fix CVE-2023-27859?
To mitigate CVE-2023-27859, update to the latest available version of IBM Db2 that resolves this issue.
What versions of IBM Db2 are affected by CVE-2023-27859?
CVE-2023-27859 affects IBM Db2 versions 10.1, 10.5, 11.1, and 11.5.
What may happen if I don't address CVE-2023-27859?
Failure to address CVE-2023-27859 could result in unauthorized remote code execution within your Db2 environment.
Can CVE-2023-27859 affect databases on different servers?
Yes, CVE-2023-27859 allows a malicious user to exploit vulnerable jar file installations across multiple databases, even if they are hosted on different servers.