Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2021-42392

больше 4 лет назад

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2021-42392

больше 4 лет назад

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2021-42392

больше 4 лет назад

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2021-42392

больше 4 лет назад

The org.h2.util.JdbcUtils.getConnection method of the H2 database take ...

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-h376-j262-vhq6

больше 4 лет назад

RCE in H2 Console

CVSS3: 9.8
EPSS: Средний
fstec логотип

BDU:2022-00195

больше 4 лет назад

Уязвимость метода org.h2.util.JdbcUtils.getConnection системы управления базами данных H2, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-42392

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVSS3: 9.8
63%
Средний
больше 4 лет назад
redhat логотип
CVE-2021-42392

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVSS3: 9.8
63%
Средний
больше 4 лет назад
nvd логотип
CVE-2021-42392

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.

CVSS3: 9.8
63%
Средний
больше 4 лет назад
debian логотип
CVE-2021-42392

The org.h2.util.JdbcUtils.getConnection method of the H2 database take ...

CVSS3: 9.8
63%
Средний
больше 4 лет назад
github логотип
GHSA-h376-j262-vhq6

RCE in H2 Console

CVSS3: 9.8
63%
Средний
больше 4 лет назад
fstec логотип
BDU:2022-00195

Уязвимость метода org.h2.util.JdbcUtils.getConnection системы управления базами данных H2, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
63%
Средний
больше 4 лет назад

Уязвимостей на страницу