First published: Wed Jan 19 2022(Updated: )
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/com.h2database:h2 | <2.1.210 | 2.1.210 |
redhat/eap7-h2database | <0:1.4.197-2.redhat_00004.1.el8ea | 0:1.4.197-2.redhat_00004.1.el8ea |
redhat/eap7-h2database | <0:1.4.197-2.redhat_00004.1.el7ea | 0:1.4.197-2.redhat_00004.1.el7ea |
debian/h2database | 1.4.197-4+deb10u1 1.4.197-4+deb11u1 2.1.214-1 2.2.220-1 | |
redhat/h2 | <2.1.210 | 2.1.210 |
H2database H2 | >=1.1.100<2.0.206 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Oracle Communications Cloud Native Core Console | =1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2022-23221 is a vulnerability in H2 Console that allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL.
CVE-2022-23221 is considered critical with a severity score of 9.8.
An attacker can exploit CVE-2022-23221 by using a specially crafted JDBC URL to execute arbitrary code remotely.
EAP7 H2 Database versions 0:1.4.197-2.redhat_00004.1.el8ea and 0:1.4.197-2.redhat_00004.1.el7ea are affected, as well as H2 Database version up to 2.0.206 and H2 versions up to 2.1.210.
To mitigate the CVE-2022-23221 vulnerability, update to H2 Console version 2.1.210 or later.