Логотип exploitDog
bind:"GHSA-77xx-rxvh-q682" OR bind:"CVE-2022-41853"
Консоль
Логотип exploitDog

exploitDog

bind:"GHSA-77xx-rxvh-q682" OR bind:"CVE-2022-41853"

Количество 9

Количество 9

github логотип

GHSA-77xx-rxvh-q682

почти 3 года назад

HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

CVSS3: 9.8
EPSS: Высокий
ubuntu логотип

CVE-2022-41853

почти 3 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
EPSS: Высокий
redhat логотип

CVE-2022-41853

почти 3 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2022-41853

почти 3 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
EPSS: Высокий
debian логотип

CVE-2022-41853

почти 3 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ...

CVSS3: 8
EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:3864-1

почти 3 года назад

Security update for hsqldb

EPSS: Высокий
suse-cvrf логотип

SUSE-SU-2022:3823-1

почти 3 года назад

Security update for hsqldb

EPSS: Высокий
oracle-oval логотип

ELSA-2023-12103

больше 2 лет назад

ELSA-2023-12103: hsqldb security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8560

почти 3 года назад

ELSA-2022-8560: hsqldb security update (IMPORTANT)

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-77xx-rxvh-q682

HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

CVSS3: 9.8
71%
Высокий
почти 3 года назад
ubuntu логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
71%
Высокий
почти 3 года назад
redhat логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 9.8
71%
Высокий
почти 3 года назад
nvd логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
71%
Высокий
почти 3 года назад
debian логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ...

CVSS3: 8
71%
Высокий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3864-1

Security update for hsqldb

71%
Высокий
почти 3 года назад
suse-cvrf логотип
SUSE-SU-2022:3823-1

Security update for hsqldb

71%
Высокий
почти 3 года назад
oracle-oval логотип
ELSA-2023-12103

ELSA-2023-12103: hsqldb security update (IMPORTANT)

больше 2 лет назад
oracle-oval логотип
ELSA-2022-8560

ELSA-2022-8560: hsqldb security update (IMPORTANT)

почти 3 года назад

Уязвимостей на страницу