Логотип exploitDog
bind:CVE-2021-23463
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-23463

Количество 6

Количество 6

ubuntu логотип

CVE-2021-23463

около 4 лет назад

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

CVSS3: 8.1
EPSS: Низкий
redhat логотип

CVE-2021-23463

больше 4 лет назад

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2021-23463

около 4 лет назад

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2021-23463

около 4 лет назад

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vuln ...

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-7rpj-hg47-cx62

около 4 лет назад

Improper Restriction of XML External Entity Reference in com.h2database:h2.

CVSS3: 8.1
EPSS: Низкий
fstec логотип

BDU:2024-02259

около 4 лет назад

Уязвимость пакета com.h2database:h2 системы управления базами данных H2, позволяющая нарушителю проводить XXE-атаки

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2021-23463

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

CVSS3: 8.1
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-23463

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

CVSS3: 6.8
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-23463

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

CVSS3: 8.1
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-23463

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vuln ...

CVSS3: 8.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-7rpj-hg47-cx62

Improper Restriction of XML External Entity Reference in com.h2database:h2.

CVSS3: 8.1
0%
Низкий
около 4 лет назад
fstec логотип
BDU:2024-02259

Уязвимость пакета com.h2database:h2 системы управления базами данных H2, позволяющая нарушителю проводить XXE-атаки

CVSS3: 8.1
0%
Низкий
около 4 лет назад

Уязвимостей на страницу