PT-2026-39186 · Amazon · Amazon Redshift Jdbc Driver
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Amazon Redshift JDBC Driver versions prior to 2.2.2
Description
An issue allows the driver to load and execute arbitrary classes when processing JDBC connection URL parameters. An actor capable of influencing the connection URL could potentially execute code within the application context, provided a suitable class exists on the application's classpath.
Recommendations
Upgrade to version 2.2.2 or later.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Amazon Redshift Jdbc Driver