PT-2025-42627 · H2+1 · H2+1
Published
2025-10-17
·
Updated
2025-10-17
·
CVE-2025-62420
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DataEase versions through 2.10.13
Description
DataEase is a data visualization and analytics platform. A JDBC driver bypass exists in the H2 database connection handler. The
getJdbc function in H2.java checks if the jdbcUrl starts with jdbc:h2 but uses a separate jdbc field as the actual connection URL. An attacker can provide a jdbcUrl starting with jdbc:h2 while supplying a different jdbc field with an arbitrary JDBC driver and connection string. This allows an authenticated attacker to trigger arbitrary JDBC connections with malicious drivers, potentially leading to remote code execution.Recommendations
Update to DataEase version 2.10.14 or later.
Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dataease
H2