DataGear JDBC Server deserialization
CVE-2023-2042

8.8HIGH

Key Information:

Vendor

Datagear

Status
Vendor
CVE Published:
14 April 2023

What is CVE-2023-2042?

A vulnerability has been discovered in the JDBC Server Handler component of DataGear, affecting versions up to 4.7.0 and 5.1.0. This issue allows for remote manipulation, leading to deserialization attacks. The vulnerability has been disclosed publicly, raising concerns about potential exploitation. Despite early notification to the vendor, no response has been received, leaving users at risk.

Affected Version(s)

DataGear 4.0

DataGear 4.1

DataGear 4.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yangyanglo (VulDB User)
.