Dataease

Dataease

57 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.13%
  • Veröffentlicht 25.08.2025 17:00:20
  • Zuletzt bearbeitet 03.09.2025 13:41:43

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If the JDBC URL meets criteria, the getJdbcUrl method is returned, which acts as the getter for the Jdb...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 25.08.2025 16:42:11
  • Zuletzt bearbeitet 03.09.2025 13:43:01

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 02.07.2025 14:22:31
  • Zuletzt bearbeitet 10.07.2025 15:16:32

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreSQL and Redshift, apart from parameters like "socketfactory" and "socketfactoryarg", there are also "sslfactory" and "sslfactoryarg...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 01.07.2025 00:33:53
  • Zuletzt bearbeitet 16.07.2025 14:43:07

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's PostgreSQL Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 30.06.2025 20:18:49
  • Zuletzt bearbeitet 10.07.2025 13:42:12

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, there is a bypass vulnerability in Dataease's Redshift Data Source JDBC Connection Parameters. The sslfactory and sslfactoryarg parameters could t...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 26.06.2025 13:51:44
  • Zuletzt bearbeitet 09.07.2025 18:47:27

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor may take advantage of a feature in Java in which the character "ı" becomes "I" when converted to uppercase, and the character "ſ" b...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 03.06.2025 20:37:40
  • Zuletzt bearbeitet 05.06.2025 14:07:36

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are ...

  • EPSS 0.08%
  • Veröffentlicht 03.06.2025 20:33:48
  • Zuletzt bearbeitet 05.06.2025 14:07:47

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.10, secret verification does not take effect successfully, so a user can use any secret to forge a JWT token. The vulnerability has been fixed in v2.1...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 03.06.2025 20:31:13
  • Zuletzt bearbeitet 05.06.2025 14:07:58

DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns fa...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 03.06.2025 18:27:43
  • Zuletzt bearbeitet 09.06.2025 15:13:08

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection....