← back
CVE-2018-10054

CVE-2018-10054

30Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendepss 34%
from disclosure to weapon0 days
Published on NVDApr 11
metasploitApr 9
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
Affected products
n/a · n/a