Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m452-g496-4chp

Опубликовано: 11 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6.9

Описание

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.

EPSS

Процентиль: 6%
0.00024
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.9
nvd
3 месяца назад

Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application.

CVSS3: 6.9
fstec
3 месяца назад

Уязвимость клиента для взаимодействия с базой данных SAP HANA через JDBC SAP HANA JDBC Client, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 6%
0.00024
Низкий

6.9 Medium

CVSS3

Дефекты

CWE-94