Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. The vulnerability has been fixed in version 2.10.17.
History

Fri, 21 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Nov 2025 17:15:00 +0000

Type Values Removed Values Added
Description Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. The vulnerability has been fixed in version 2.10.17.
Title DataEase DB2 JNDI Vulnerability
Weaknesses CWE-74
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-11-20T17:07:00.575Z

Updated: 2025-11-21T16:18:57.597Z

Reserved: 2025-11-03T22:12:51.364Z

Link: CVE-2025-64428

cve-icon Vulnrichment

Updated: 2025-11-21T16:18:39.028Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-11-20T17:15:53.197

Modified: 2025-11-21T17:15:51.493

Link: CVE-2025-64428

cve-icon Redhat

No data.