Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40684
HistoryMay 25, 2023 - 3:20 a.m.

Remote Code Execution (RCE)

2023-05-2503:20:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
63
remote code execution
sqlite-jdbc
jdbc url
vulnerability
injection
malicious code

EPSS

0.015

Percentile

87.0%

sqlite-jdbc is vulnerable to Remote Code Execution (RCE). The vulnerability exists because the extractResource function of SQLiteConnection.java does not properly validate the user input URL, which allows an attacker to inject and execute malicious code through the JDBC URL