Количество 10
Количество 10
BDU:2026-01710
Уязвимость системы управления базами данных HyperSQL DataBase (HSQLDB), связанная с применением входных данных с внешним управлением для выбора классов, позволяющая нарушителю выполнить произвольный код
CVE-2022-41853
Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.
CVE-2022-41853
Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.
CVE-2022-41853
Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.
CVE-2022-41853
Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ...
SUSE-SU-2022:3864-1
Security update for hsqldb
SUSE-SU-2022:3823-1
Security update for hsqldb
GHSA-77xx-rxvh-q682
HyperSQL DataBase vulnerable to remote code execution when processing untrusted input
ELSA-2023-12103
ELSA-2023-12103: hsqldb security update (IMPORTANT)
ELSA-2022-8560
ELSA-2022-8560: hsqldb security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-01710 Уязвимость системы управления базами данных HyperSQL DataBase (HSQLDB), связанная с применением входных данных с внешним управлением для выбора классов, позволяющая нарушителю выполнить произвольный код | CVSS3: 9.8 | 4% Низкий | около 4 лет назад | |
CVE-2022-41853 Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled. | CVSS3: 8 | 4% Низкий | почти 4 года назад | |
CVE-2022-41853 Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled. | CVSS3: 9.8 | 4% Низкий | почти 4 года назад | |
CVE-2022-41853 Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled. | CVSS3: 8 | 4% Низкий | почти 4 года назад | |
CVE-2022-41853 Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ... | CVSS3: 8 | 4% Низкий | почти 4 года назад | |
SUSE-SU-2022:3864-1 Security update for hsqldb | 4% Низкий | почти 4 года назад | ||
SUSE-SU-2022:3823-1 Security update for hsqldb | 4% Низкий | почти 4 года назад | ||
GHSA-77xx-rxvh-q682 HyperSQL DataBase vulnerable to remote code execution when processing untrusted input | CVSS3: 9.8 | 4% Низкий | почти 4 года назад | |
ELSA-2023-12103 ELSA-2023-12103: hsqldb security update (IMPORTANT) | 4% Низкий | больше 3 лет назад | ||
ELSA-2022-8560 ELSA-2022-8560: hsqldb security update (IMPORTANT) | 4% Низкий | больше 3 лет назад |
Уязвимостей на страницу