PT-2025-38663 · Unknown · H2Oai/H2O-3+1

Ez-Lbz

·

Published

2025-09-21

·

Updated

2025-09-21

·

CVE-2025-10769

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions h2oai h2o-3 versions through 3.46.08
Description A vulnerability exists in h2oai h2o-3 up to version 3.46.08, specifically within the H2 JDBC Driver component. The issue involves the manipulation of the connection url argument in the /99/ImportSQLTable file, leading to deserialization. This can be exploited remotely. The exploit has been publicly disclosed.
Recommendations Versions prior to 3.46.08 are affected. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-10769

Affected Products

H2 Jdbc Driver
H2Oai/H2O-3