CVE-2024-55551
CVE-2024-55551
Título es
CVE-2024-55551
Mié, 19/03/2025 – 14:15
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-55551
Descripción en
An issue was discovered in Exasol jdbc driver 24.2.0. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution vulnerability.
19/03/2025
19/03/2025
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Referencias
https://docs.exasol.com/db/latest/connect_exasol/drivers/jdbc.htm
https://gist.github.com/azraelxuemo/9565ec9219e0c3e9afd5474904c39d0f
https://www.blackhat.com/eu-24/briefings/schedule/index.html#a-novel-attack-surface-java-authentication-and-authorization-service-jaas-42179
Enviar en el boletín
Off
