Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 10

Количество 10

github логотип

GHSA-77xx-rxvh-q682

почти 4 года назад

HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2022-41853

почти 4 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
EPSS: Низкий
redhat логотип

CVE-2022-41853

почти 4 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-41853

почти 4 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
EPSS: Низкий
debian логотип

CVE-2022-41853

почти 4 года назад

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ...

CVSS3: 8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3864-1

почти 4 года назад

Security update for hsqldb

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2022:3823-1

почти 4 года назад

Security update for hsqldb

EPSS: Низкий
oracle-oval логотип

ELSA-2023-12103

больше 3 лет назад

ELSA-2023-12103: hsqldb security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2022-8560

больше 3 лет назад

ELSA-2022-8560: hsqldb security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2026-01710

около 4 лет назад

Уязвимость системы управления базами данных HyperSQL DataBase (HSQLDB), связанная с применением входных данных с внешним управлением для выбора классов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-77xx-rxvh-q682

HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

CVSS3: 9.8
4%
Низкий
почти 4 года назад
ubuntu логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
4%
Низкий
почти 4 года назад
redhat логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 9.8
4%
Низкий
почти 4 года назад
nvd логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", "abc") or Java argument -Dhsqldb.method_class_names="abc" can be used. From version 2.7.1 all classes by default are not accessible except those in java.lang.Math and need to be manually enabled.

CVSS3: 8
4%
Низкий
почти 4 года назад
debian логотип
CVE-2022-41853

Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb ...

CVSS3: 8
4%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:3864-1

Security update for hsqldb

4%
Низкий
почти 4 года назад
suse-cvrf логотип
SUSE-SU-2022:3823-1

Security update for hsqldb

4%
Низкий
почти 4 года назад
oracle-oval логотип
ELSA-2023-12103

ELSA-2023-12103: hsqldb security update (IMPORTANT)

4%
Низкий
больше 3 лет назад
oracle-oval логотип
ELSA-2022-8560

ELSA-2022-8560: hsqldb security update (IMPORTANT)

4%
Низкий
больше 3 лет назад
fstec логотип
BDU:2026-01710

Уязвимость системы управления базами данных HyperSQL DataBase (HSQLDB), связанная с применением входных данных с внешним управлением для выбора классов, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
4%
Низкий
около 4 лет назад

Уязвимостей на страницу