PT-2025-14799 · Insightsoftware · Insightsoftware Hive Jdbc
Published
2025-04-03
·
Updated
2025-04-04
·
CVE-2024-45199
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
insightsoftware Hive JDBC versions prior to 2.6.14
Description
The issue allows for remote code execution via JNDI injection. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
Recommendations
For insightsoftware Hive JDBC versions prior to 2.6.14, update to version 2.6.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the JDBC URL to minimize the risk of exploitation. Avoid using malicious parameters in the JDBC URL until the issue is resolved.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Insightsoftware Hive Jdbc