CVE-2025-10771: jeecgboot JimuReport DB2 JDBC testConnection deserialization
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10771?
The severity of CVE-2025-10771 is considered high due to the potential for remote code execution.
How do I fix CVE-2025-10771?
To fix CVE-2025-10771, update jeecgboot JimuReport to version 2.1.3 or later.
What systems are affected by CVE-2025-10771?
CVE-2025-10771 affects jeecgboot JimuReport versions up to and including 2.1.2 and the DB2 JDBC Handler.
What type of vulnerability is CVE-2025-10771?
CVE-2025-10771 is a deserialization vulnerability that can be exploited through the DB2 JDBC Handler.
Is CVE-2025-10771 remote or local?
CVE-2025-10771 is a remote vulnerability, allowing attackers to exploit it over a network.