SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-10054

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.

HIGH 8.8EPSS 33.9%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 33.9%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
33.93% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-20
Affected
cognitect/datomic · h2database/h2
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.