Deserialization Vulnerability in h2oai h2o-3 by IBMDB2 JDBC Driver
CVE-2025-10768
Key Information:
Badges
What is CVE-2025-10768?
A vulnerability exists in h2oai's h2o-3 versions up to 3.46.08, specifically in an unknown function of the /99/ImportSQLTable file related to the IBMDB2 JDBC Driver. This flaw allows remote attackers to manipulate the connection_url argument, leading to potential deserialization attacks. The exploit has been publicly disclosed and could pose significant risks if not addressed. Despite early communication, the vendor has not provided a response regarding this vulnerability.
Affected Version(s)
h2o-3 3.46.08
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved