CVE-2025-48998: Dataease MYSQL JDBC File Reading Vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass of the patch for CVE-2025-27103 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.10. No known workarounds are available.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48998?
The severity of CVE-2025-48998 is classified as a medium risk due to its potential for data exposure.
How do I fix CVE-2025-48998?
To fix CVE-2025-48998, upgrade to DataEase version 2.10.6 or later where the vulnerability is patched.
Who is affected by CVE-2025-48998?
CVE-2025-48998 affects users of DataEase versions prior to 2.10.6 who have authenticated access.
What is the impact of CVE-2025-48998?
The impact of CVE-2025-48998 allows authenticated users to read and deserialize arbitrary files through a background JDBC connection.
Is there a workaround for CVE-2025-48998?
Currently, the recommended approach is to upgrade to the fixed version as no official workaround has been documented.