Dataease
cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*, +1 more
- < 2.10.17
A JNDI injection vulnerability exists in Dataease versions prior to 2.10.17. Although a blacklist was implemented in version 2.10.14 to mitigate this issue, JNDI injection can still be exploited using the iiop, corbaname, and iiopname schemes.
Exploitation of this vulnerability allows for JNDI injection, which could lead to remote code execution or other malicious actions, depending on the context.
Users can upgrade to Dataease version 2.10.17 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.