PT-2025-45170 · Dataease+1 · Dataease+1

Published

2025-11-06

·

Updated

2025-11-11

·

CVE-2025-64164

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dataease versions 2.10.14 and below
Description Dataease is an open source data visualization analysis tool. Versions 2.10.14 and below do not properly filter when establishing JDBC connections to Oracle, which can lead to a Java Naming and Directory Interface (JNDI) injection. JNDI is a Java API for looking up data and objects through a naming service.
Recommendations Update to version 2.10.15 or later.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2025-64164
GHSA-Q754-4PC2-WJQW

Affected Products

Dataease
Oracle