ZeroHour

CVE-2024-55551

CVSS 3.1
8.3 high
EPSS
<1%p48
Published
()
Modified
Description

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.

Vendors
exasol
Products
jdbc driver
Weakness
CWE-471
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.