Записи h2database
6 опубликованных записей вендора h2database.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 16,7 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 83,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-20 Improper Input Validation1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-502 Deserialization of Untrusted Data1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
- CWE-611 Improper Restriction of XML External Entity Reference1
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEПрофиль атаки
Все записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
64На этой неделе | CVE-2021-42392Proof of concept | The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database.h2database · h2 · CWE-502 | Критическая9,8 | — | 83,2 % | 10 янв. 2022 г. |
58В плане | CVE-2022-23221Proof of concept | H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGh2database · h2 · CWE-88 | Критическая9,8 | — | 64,8 % | 19 янв. 2022 г. |
45В плане | CVE-2018-10054Готовый эксплойт | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Jcognitect · datomic · CWE-20 | Высокая8,8 | — | 33,7 % | 11 апр. 2018 г. |
37Наблюдать | CVE-2021-23463Эксплойта нет | XML External Entity (XXE) Injectionh2database · h2 · CWE-611 | Критическая9,1 | — | 2,7 % | 10 дек. 2021 г. |
31Наблюдать | CVE-2022-45868Эксплойта нет | The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allowh2database · h2 · CWE-312 | Высокая7,8 | — | 0,3 % | 23 нояб. 2022 г. |
30Наблюдать | CVE-2018-14335Proof of concept | An issue was discovered in H2 1.4.197.h2database · h2 · CWE-59 | Средняя6,5 | — | 13,2 % | 24 июл. 2018 г. |
- CVE-2021-4239264На этой неделе
The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database.
КритическаяCVSS 9,8Proof of conceptEPSS 83 %h2database · h210 янв. 2022 г.
- CVE-2022-2322158В плане
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTING
КритическаяCVSS 9,8Proof of conceptEPSS 65 %h2database · h219 янв. 2022 г.
- CVE-2018-1005445В плане
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary J
ВысокаяCVSS 8,8Готовый эксплойтEPSS 34 %cognitect · datomic11 апр. 2018 г.
- CVE-2021-2346337Наблюдать
XML External Entity (XXE) Injection
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %h2database · h210 дек. 2021 г.
- CVE-2022-4586831Наблюдать
The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allow
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %h2database · h223 нояб. 2022 г.
- CVE-2018-1433530Наблюдать
An issue was discovered in H2 1.4.197.
СредняяCVSS 6,5Proof of conceptEPSS 13 %h2database · h224 июл. 2018 г.