PT-2025-38663 · Unknown · H2 Jdbc Driver+1

·

CVE-2025-10769

·

Published

2025-09-21

·

Updated

2025-09-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions h2oai h2o-3 versions through 3.46.08
Description A vulnerability exists in h2oai h2o-3 up to version 3.46.08, specifically within the H2 JDBC Driver component. The issue involves the manipulation of the connection url argument in the /99/ImportSQLTable file, leading to deserialization. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 3.46.08 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10769

Affected Products

H2 Jdbc Driver
H2Oai/H2O-3