Логотип exploitDog
bind:"CVE-2022-41853"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2022-41853"

Количество 9

Количество 9

ubuntu логотип

CVE-2022-41853

больше 3 лет назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
EPSS: Высокий
redhat логотип

CVE-2022-41853

больше 3 лет назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2022-41853

больше 3 лет назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
EPSS: Высокий
debian логотип

CVE-2022-41853

больше 3 лет назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ...

CVSS3: 8
EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:3864-1

больше 3 лет назад

Security update for hsqldb

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:3823-1

больше 3 лет назад

Security update for hsqldb

EPSS: Высокий
github логотип

GHSA-77xx-rxvh-q682

больше 3 лет назад

HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

CVSS3: 9.8
EPSS: Высокий
oracle-oval логотип

ELSA-2023-12103

почти 3 года назад

ELSA-2023-12103: hsqldb security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8560

около 3 лет назад

ELSA-2022-8560: hsqldb security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
70%
Высокий
больше 3 лет назад
redhat логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 9.8
70%
Высокий
больше 3 лет назад
nvd логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
70%
Высокий
больше 3 лет назад
debian логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ...

CVSS3: 8
70%
Высокий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3864-1

Security update for hsqldb

70%
Высокий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2022:3823-1

Security update for hsqldb

70%
Высокий
больше 3 лет назад
github логотип
GHSA-77xx-rxvh-q682

HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

CVSS3: 9.8
70%
Высокий
больше 3 лет назад
oracle-oval логотип
ELSA-2023-12103

ELSA-2023-12103: hsqldb security update (IMPORTANT)

почти 3 года назад
oracle-oval логотип
ELSA-2022-8560

ELSA-2022-8560: hsqldb security update (IMPORTANT)

около 3 лет назад

Уязвимостей на страницу