h2database records
6 published records for vendor h2database.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 16.7%
- Pre-auth RCE
- 2
- With a fix record
- 83.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-20 Improper Input Validation1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-502 Deserialization of Untrusted Data1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
64This week | CVE-2021-42392Proof of concept | The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database.h2database · h2 · CWE-502 | Critical9.8 | — | 83.2% | Jan 10, 2022 |
58Plan | CVE-2022-23221Proof of concept | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGh2database · h2 · CWE-88 | Critical9.8 | — | 64.8% | Jan 19, 2022 |
45Plan | CVE-2018-10054Weaponized | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Jcognitect · datomic · CWE-20 | High8.8 | — | 33.7% | Apr 11, 2018 |
37Monitor | CVE-2021-23463No exploit | XML External Entity (XXE) Injectionh2database · h2 · CWE-611 | Critical9.1 | — | 2.7% | Dec 10, 2021 |
31Monitor | CVE-2022-45868No exploit | The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allowh2database · h2 · CWE-312 | High7.8 | — | 0.3% | Nov 23, 2022 |
30Monitor | CVE-2018-14335Proof of concept | An issue was discovered in H2 1.4.197.h2database · h2 · CWE-59 | Medium6.5 | — | 13.2% | Jul 24, 2018 |
- CVE-2021-4239264This week
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database.
CriticalCVSS 9.8Proof of conceptEPSS 83%h2database · h2Jan 10, 2022
- CVE-2022-2322158Plan
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING
CriticalCVSS 9.8Proof of conceptEPSS 65%h2database · h2Jan 19, 2022
- CVE-2018-1005445Plan
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary J
HighCVSS 8.8WeaponizedEPSS 34%cognitect · datomicApr 11, 2018
- CVE-2021-2346337Monitor
XML External Entity (XXE) Injection
CriticalCVSS 9.1No exploitEPSS 3%h2database · h2Dec 10, 2021
- CVE-2022-4586831Monitor
The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allow
HighCVSS 7.8No exploitEPSS 0%h2database · h2Nov 23, 2022
- CVE-2018-1433530Monitor
An issue was discovered in H2 1.4.197.
MediumCVSS 6.5Proof of conceptEPSS 13%h2database · h2Jul 24, 2018