CVE-2022-41853 — Unsafe Reflection in Database Hsqldb
Severity
9.8CRITICALNVD
EPSS
70.1%
top 1.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 6
Latest updateApr 15
Description
Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, System.setProperty("hsqldb.method_class_names", …
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9
Affected Packages4 packages
Also affects: Debian Linux 10.0, 11.0
🔴Vulnerability Details
3📋Vendor Advisories
4Oracle▶
Oracle Oracle Insurance Applications Risk Matrix: Enterprise Edition (HyperSQL Database) — CVE-2022-41853↗2024-04-15
Oracle▶
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (HyperSQL Database) — CVE-2022-41853↗2023-07-15
Debian▶
CVE-2022-41853: hsqldb - Those using java.sql.Statement or java.sql.PreparedStatement in hsqldb (HyperSQL...↗2022