PT-2025-34683 · Ibm+2 · Db2+3

For-A1Kaid

+2

·

Published

2025-08-25

·

Updated

2025-10-24

·

CVE-2025-57773

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DataEase versions prior to 2.10.12
Description: DataEase is an open source business intelligence and data visualization tool. Due to insufficient filtering of DB2 parameters, a JNDI injection attack can be launched, triggering an AspectJWeaver deserialization attack that results in writing to various files. This vulnerability requires commons-collections 4.x and aspectjweaver-1.9.22.jar.
Recommendations: Update DataEase to version 2.10.12 or later.

Exploit

Fix

RCE

Code Injection

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-57773
GHSA-7R8J-6WHV-4J5P

Affected Products

Db2
Dataease
Aspectjweaver-1.9.22.Jar
Commons-Collections