CVE-2025-57773: Dataease DB2 Aspectweaver Deserialization Arbitrary File Write Vulnerability
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files. This vulnerability requires commons-collections 4.x and aspectjweaver-1.9.22.jar. The vulnerability has been fixed in version 2.10.12.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-57773?
CVE-2025-57773 is a critical vulnerability due to the potential for JNDI injection attacks.
How do I fix CVE-2025-57773?
To fix CVE-2025-57773, upgrade DataEase to version 2.10.12 or later.
What type of attack is associated with CVE-2025-57773?
CVE-2025-57773 is associated with JNDI injection and deserialization attacks.
Could CVE-2025-57773 lead to unauthorized access?
Yes, CVE-2025-57773 could potentially enable unauthorized access to sensitive files on the server.
Which versions of DataEase are affected by CVE-2025-57773?
Versions of DataEase prior to 2.10.12 are affected by CVE-2025-57773.