Metrics
Affected Vendors & Products
Mon, 22 Sep 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 22 Sep 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
H2oai
H2oai h2o-3 |
|
Vendors & Products |
H2oai
H2oai h2o-3 |
Sun, 21 Sep 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQLTable of the component IBMDB2 JDBC Driver. This manipulation of the argument connection_url causes deserialization. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | h2oai h2o-3 IBMDB2 JDBC Driver ImportSQLTable deserialization | |
Weaknesses | CWE-20 CWE-502 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-09-22T17:24:16.558Z
Reserved: 2025-09-21T08:16:05.733Z
Link: CVE-2025-10768

Updated: 2025-09-22T17:24:05.400Z

Status : Awaiting Analysis
Published: 2025-09-21T10:15:48.177
Modified: 2025-09-22T21:23:01.543
Link: CVE-2025-10768

No data.