JNDI Injection Vulnerability in DataEase Business Intelligence Tool
CVE-2025-57773
What is CVE-2025-57773?
An identified vulnerability in DataEase allows attackers to exploit unfiltered DB2 parameters to execute JNDI injection attacks. This vulnerability can lead to the triggering of an AspectJWeaver deserialization attack, enabling unauthorized writing to various files within the system. Users are encouraged to upgrade to version 2.10.12 or higher to mitigate this risk. The successful exploitation of this vulnerability requires specific libraries, namely commons-collections 4.x and aspectjweaver-1.9.22.jar, making it crucial to address this security concern promptly.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
dataease < 2.10.12
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
