H2 · H2 · CVE-2018-14335
**Name of the Vulnerable Software and Affected Versions**
H2 version 1.4.197
**Description**
An issue was discovered in the handling of permissions in the backup function, allowing attackers to read sensitive files outside of their permissions via a symlink to a fake database file.
**Recommendations**
For H2 version 1.4.197, consider disabling the backup function until a patch is available to prevent attackers from reading sensitive files. Restrict access to sensitive files and directories to minimize the risk of exploitation.