CVE-2023-27859

IBM Db2 10.1, 10.5, and 11.1 could allow a remote user to execute arbitrary code caused by installing like named jar files across multiple databases. A user could exploit this by installing a malicious jar file that overwrites the existing like named jar file in another database. IBM X-Force ID: 249205.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
cpe:2.3:a:ibm:db2:*:*:*:*:*:*:*:*
OR cpe:2.3:o:hp:hp-ux:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:aix:-:*:*:*:*:*:*:*
cpe:2.3:o:ibm:linux_on_ibm_z:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:oracle:solaris:-:*:*:*:*:*:*:*

History

20 Jun 2025, 19:15

Type Values Removed Values Added
CWE CWE-427

Information

Published : 2024-01-22 20:15

Updated : 2025-06-20 19:15


NVD link : CVE-2023-27859

Mitre link : CVE-2023-27859

CVE.ORG link : CVE-2023-27859


JSON object : View

Products Affected

hp

  • hp-ux

ibm

  • db2
  • linux_on_ibm_z
  • aix

microsoft

  • windows

oracle

  • solaris

linux

  • linux_kernel
CWE
NVD-CWE-noinfo CWE-427

Uncontrolled Search Path Element