Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-87612
HistoryOct 10, 2022 - 12:00 a.m.

HSQLDB Code Execution Vulnerability

2022-10-1000:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
hsqldb
code execution
vulnerability
untrusted input
java
static method
attacker
cnvd

EPSS

0.013

Percentile

85.7%

HSQLDB is a relational database management system written in Java by The HSQL Development Group team. HSQLDB suffers from a code execution vulnerability that stems from its use of java.sql.Statement or java.sql.PreparedStatement to handle untrusted input, which by default allows calls to any Any static method of a Java class can be exploited by an attacker to execute code.