← volver
CVE-2025-10771

jeecgboot JimuReport DB2 JDBC testConnection deserialization

CVSS 5.3 MEDIUMEPSS 0.6%CWE-20CWE-502
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 5.3EPSS 0.6%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
21 sep 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Productos afectados
jeecgboot · JimuReport

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →