PT-2025-17642 · Dataease · Dataease

N1Etzsche0

·

Published

2025-04-23

·

Updated

2025-06-04

·

CVE-2025-32966

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DataEase versions prior to 2.10.8
Description The issue allows authenticated users to complete remote code execution (RCE) through the backend JDBC link.
Recommendations For versions prior to 2.10.8, update to version 2.10.8 to resolve the issue. As a temporary workaround, consider restricting access to the backend JDBC link until the update is applied.

Exploit

Fix

RCE

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-32966
GHSA-H7HJ-4J78-CVC7

Affected Products

Dataease