CVE-2024-55551

An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
Configurations

No configuration.

History

02 Apr 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.0
v2 : unknown
v3 : 8.3

25 Mar 2025, 17:16

Type Values Removed Values Added
CWE CWE-471
Summary
  • (es) Se detectó un problema en Exasol jdbc driver 24.2.0. Los atacantes pueden inyectar parámetros maliciosos en la URL de JDBC, lo que activa la inyección JNDI durante el proceso cuando el controlador JDBC utiliza esta URL para conectarse a la base de datos. Esto puede generar una vulnerabilidad de ejecución remota de código.
Summary (en) An issue was discovered in Exasol jdbc driver 24.2.0. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution vulnerability. (en) An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 9.0
References
  • () https://docs.exasol.com/db/7.1/release_notes_drivers_jdbc/24.2.1.htm -

19 Mar 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-94

19 Mar 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-19 14:15

Updated : 2025-04-02 14:15


NVD link : CVE-2024-55551

Mitre link : CVE-2024-55551

CVE.ORG link : CVE-2024-55551


JSON object : View

Products Affected

No product.

CWE
CWE-471

Modification of Assumed-Immutable Data (MAID)

CWE-94

Improper Control of Generation of Code ('Code Injection')