CVE-2023-27859
MEDIUMDescription
IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.
Is your site exposed to CVE-2023-27859?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| ibm | db2 |
| ibm | db2 |
| ibm | db2 |
| hp | hp-ux |
| ibm | aix |
| ibm | linux_on_ibm_z |
| linux | linux_kernel |
| microsoft | windows |
| oracle | solaris |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2023-27859? +
How severe is CVE-2023-27859? +
What products are affected by CVE-2023-27859? +
How do I check if I'm vulnerable to CVE-2023-27859? +
Related Vulnerabilities
To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH …
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load …
Rufus is a utility that helps format and create bootable USB flash drives. A DLL hijacking vulnerability in Rufus 4.6.2208 …
DLL Search Order Hijacking vulnerability potentially allowed an attacker with administrator privileges to load a malicious dynamic-link library and execute …
Uncontrolled Search Path Element vulnerability in OpenText Secure Content Manager on Windows allows DLL Side-Loading.This issue affects Secure Content Manager: …
PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without …