Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:33555
HistoryJan 07, 2022 - 9:51 a.m.

Remote Code Execution (RCE)

2022-01-0709:51:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
h2
remote code execution
vulnerability
jndi lookup
malicious code
lan
wan

EPSS

0.46

Percentile

97.5%

h2 is vulnerable to remote code execution. The vulnerability exists due to the use of javax.naming.Context.lookup method which performs JNDI lookup,as a dangerous function/sink, allowing an attacker to load custom class/ remote LDAP/RMI queries and execute malicious code in a process with H2 Console exposed to the LAN or WAN. (Note: H2 Console connection isnt always used with the H2 database and listens only localhost by default.)