CVE-2025-3164: Tencent Music Entertainment SuperSonic H2 Database Connection testConnect code injection
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-3164?
CVE-2025-3164 has been rated as critical due to the potential impact on system integrity.
How do I fix CVE-2025-3164?
To fix CVE-2025-3164, upgrade Tencent SuperSonic to a version later than 0.9.8 that addresses this vulnerability.
What component is affected by CVE-2025-3164?
CVE-2025-3164 affects the H2 Database Connection Handler within Tencent SuperSonic.
What functionality is impacted by CVE-2025-3164?
CVE-2025-3164 impacts the functionality related to the /api/semantic/database/testConnect endpoint.
What are the consequences of exploiting CVE-2025-3164?
Exploiting CVE-2025-3164 may lead to unauthorized access and manipulation of database connections.