CVE-2026-32939
- EPSS 0.05%
- Veröffentlicht 20.03.2026 03:27:46
- Zuletzt bearbeitet 20.03.2026 13:37:50
DataEase is an open source data visualization analysis tool. Versions 2.10.19 and below have inconsistent Locale handling between the JDBC URL validation logic and the H2 JDBC engine's internal parsing. DataEase uses String.toUpperCase() without spec...
CVE-2026-32140
- EPSS 0.35%
- Veröffentlicht 12.03.2026 18:16:25
- Zuletzt bearbeitet 13.03.2026 19:54:40
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, By controlling the IniFile parameter, an attacker can force the JDBC driver to load an attacker-controlled configuration file. This configuration file can inject dangerous...
CVE-2026-32139
- EPSS 0.08%
- Veröffentlicht 12.03.2026 18:16:25
- Zuletzt bearbeitet 13.03.2026 16:02:45
Dataease is an open source data visualization analysis tool. In DataEase 2.10.19 and earlier, the static resource upload interface allows SVG uploads. However, backend validation only checks whether the XML is parseable and whether the root node is s...
CVE-2026-32137
- EPSS 0.06%
- Veröffentlicht 12.03.2026 17:53:00
- Zuletzt bearbeitet 13.03.2026 16:03:02
Dataease is an open source data visualization analysis tool. Prior to 2.10.20, The table parameter for /de2api/datasource/previewData is directly concatenated into the SQL statement without any filtering or parameterization. Since tableName is a user...
CVE-2026-23958
- EPSS 0.03%
- Veröffentlicht 22.01.2026 01:42:11
- Zuletzt bearbeitet 17.02.2026 16:28:47
Dataease is an open source data visualization analysis tool. Prior to version 2.10.19, DataEase uses the MD5 hash of the user’s password as the JWT signing secret. This deterministic secret derivation allows an attacker to brute-force the admin’s pas...
CVE-2025-64428
- EPSS 0.2%
- Veröffentlicht 20.11.2025 17:15:53
- Zuletzt bearbeitet 24.11.2025 14:21:01
Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iio...
CVE-2025-64164
- EPSS 0.09%
- Veröffentlicht 06.11.2025 00:07:58
- Zuletzt bearbeitet 07.11.2025 18:06:49
Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Interface inje...
CVE-2025-64163
- EPSS 0.1%
- Veröffentlicht 05.11.2025 23:52:05
- Zuletzt bearbeitet 07.11.2025 18:06:36
DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist to filter ldap:// and ldaps://. However, omission of protection for the dns:// protocol results in an SSRF vulnerability. This is...
CVE-2025-62419
- EPSS 0.08%
- Veröffentlicht 17.10.2025 17:11:21
- Zuletzt bearbeitet 24.10.2025 16:56:36
DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC URL injection vulnerability exists in the DB2 and MongoDB data source configuration handlers. In the DB2 data source handler, when the extraParams f...
CVE-2025-62420
- EPSS 0.27%
- Veröffentlicht 17.10.2025 17:11:18
- Zuletzt bearbeitet 24.10.2025 15:56:16
DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a JDBC driver bypass vulnerability exists in the H2 database connection handler. The getJdbc function in H2.java checks if the jdbcUrl starts with jdbc:h2 ...