PT-2025-26969 · Oracle+1 · Java+1
Fushuling
+1
·
Publicado
2025-06-26
·
Atualizado
2025-06-29
·
CVE-2025-49003
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DataEase versions prior to 2.10.11
Description:
The issue concerns a feature in Java where certain characters are converted to their uppercase equivalents, potentially allowing a threat actor to craft a message that exploits this character conversion for remote code execution.
Recommendations:
For versions prior to 2.10.11, update to version 2.10.11 to resolve the issue.
As a temporary workaround, consider restricting the use of Java character conversion features until the update is applied.
Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dataease
Java