PT-2025-34683 · Ibm+2 · Db2+3
For-A1Kaid
+2
·
Published
2025-08-25
·
Updated
2025-10-24
·
CVE-2025-57773
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DataEase versions prior to 2.10.12
Description:
DataEase is an open source business intelligence and data visualization tool. Due to insufficient filtering of DB2 parameters, a JNDI injection attack can be launched, triggering an AspectJWeaver deserialization attack that results in writing to various files. This vulnerability requires commons-collections 4.x and aspectjweaver-1.9.22.jar.
Recommendations:
Update DataEase to version 2.10.12 or later.
Exploit
Fix
RCE
Code Injection
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Db2
Dataease
Aspectjweaver-1.9.22.Jar
Commons-Collections