CVE-2022-23221
PoC ×3—CVSS 3.1
9.8 critical
EPSS
65%p99
Published
()
Modified
Description
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
- Vendors
- h2databasedebianoracle
- Products
- h2, debian linux, communications cloud native core console
- Weakness
- CWE-88
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.