Bypass Vulnerability in DataEase Business Intelligence Tool
CVE-2025-53004

7.8HIGH

Key Information:

Vendor

Dataease

Status
Vendor
CVE Published:
30 June 2025

What is CVE-2025-53004?

DataEase, an open source business intelligence and data visualization tool, is susceptible to a bypass vulnerability involving the sslfactory and sslfactoryarg parameters. This security flaw could allow unauthorized access or manipulation of sensitive data. It has been addressed in version 2.10.11, and users are strongly advised to upgrade to this version to mitigate potential risks.

Affected Version(s)

dataease < 2.10.11

References

CVSS V4

Score:
7.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53004 : Bypass Vulnerability in DataEase Business Intelligence Tool