CVE-2022-23221
h2: Loading of custom classes from remote servers through JNDI
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
H2 Console versiones anteriores a 2.1.210, permite a atacantes remotos ejecutar código arbitrario por medio de una URL jdbc:h2:mem JDBC que contenga la subcadena IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT, una vulnerabilidad diferente a CVE-2021-42392
A flaw was found in the H2 Console. This flaw allows remote attackers to execute arbitrary code via a JDBC URL, concatenating with a substring that allows remote code execution by using a script.
Red Hat JBoss Enterprise Application Platform 7 is a platform for Java applications based on the WildFly application runtime. This release of Red Hat JBoss Enterprise Application Platform 7.4.5 serves as a replacement for Red Hat JBoss Enterprise Application Platform 7.4.4 and includes bug fixes and enhancements. See the Red Hat JBoss Enterprise Application Platform 7.4.5 Release Notes for information about the most significant bug fixes and enhancements included in this release. Issues addressed include HTTP request smuggling, code execution, denial of service, memory leak, and traversal vulnerabilities.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-14 CVE Reserved
- 2022-01-19 CVE Published
- 2022-01-25 First Exploit
- 2024-08-03 CVE Updated
- 2025-03-31 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-88: Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (13)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2022/02/msg00017.html | Mailing List |
|
https://security.netapp.com/advisory/ntap-20230818-0011 |
|
|
https://www.oracle.com/security-alerts/cpujul2022.html | Not Applicable |
|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/165676 | 2022-01-25 | |
http://packetstormsecurity.com/files/165676/H2-Database-Console-Remote-Code-Execution.html | 2024-08-03 | |
http://seclists.org/fulldisclosure/2022/Jan/39 | 2024-08-03 | |
https://twitter.com/d0nkey_man/status/1483824727936450564 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://github.com/h2database/h2database/releases/tag/version-2.1.210 | 2023-08-18 | |
https://github.com/h2database/h2database/security/advisories | 2023-08-18 | |
https://www.oracle.com/security-alerts/cpuapr2022.html | 2023-08-18 |
URL | Date | SRC |
---|---|---|
https://www.debian.org/security/2022/dsa-5076 | 2023-08-18 | |
https://access.redhat.com/security/cve/CVE-2022-23221 | 2024-11-25 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2044596 | 2024-11-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
H2database Search vendor "H2database" | H2 Search vendor "H2database" for product "H2" | >= 1.1.100 < 2.0.206 Search vendor "H2database" for product "H2" and version " >= 1.1.100 < 2.0.206" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 9.0 Search vendor "Debian" for product "Debian Linux" and version "9.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 11.0 Search vendor "Debian" for product "Debian Linux" and version "11.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Cloud Native Core Console Search vendor "Oracle" for product "Communications Cloud Native Core Console" | 1.9.0 Search vendor "Oracle" for product "Communications Cloud Native Core Console" and version "1.9.0" | - |
Affected
|