CVE-2018-14335
H2 Database 1.4.197 - Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
Se ha descubierto un problema en H2 1.4.197. La manipulación incorrecta de permisos en la función backup permite que los atacantes lean archivos sensibles (fuera de sus permisos) mediante un vínculo simbólico a un archivo falso de base de datos.
Red Hat Data Grid is a distributed, in-memory, NoSQL datastore based on the Infinispan project. This release of Red Hat Data Grid 7.3.3 serves as a replacement for Red Hat Data Grid 7.3.2 and includes bug fixes and enhancements, which are described in the Release Notes, linked to in the References section of this erratum. Issues addressed include code execution, deserialization, and insecure handling vulnerabilities.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2018-07-16 CVE Reserved
- 2018-07-24 CVE Published
- 2018-07-30 First Exploit
- 2024-10-29 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-276: Incorrect Default Permissions
CAPEC
References (8)
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/148745 | 2018-07-30 | |
https://www.exploit-db.com/exploits/45105 | 2024-10-29 | |
https://gist.github.com/owodelta/9714faf9a86435cef5a99d4930eaee20 | 2024-10-29 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2020:0727 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-14335 | 2020-03-05 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1610877 | 2020-03-05 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
H2database Search vendor "H2database" | H2 Search vendor "H2database" for product "H2" | 1.4.197 Search vendor "H2database" for product "H2" and version "1.4.197" | - |
Affected
|