PT-2025-45170 · Dataease+1 · Dataease+1

CVE-2025-64164

·

Published

2025-11-06

·

Updated

2025-11-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dataease versions 2.10.14 and below
Description Dataease is an open source data visualization analysis tool. Versions 2.10.14 and below do not properly filter when establishing JDBC connections to Oracle, which can lead to a Java Naming and Directory Interface (JNDI) injection. JNDI is a Java API for looking up data and objects through a naming service.
Recommendations Update to version 2.10.15 or later.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-64164
GHSA-Q754-4PC2-WJQW

Affected Products

Dataease
Oracle