VulnerabilityAnalyzed
CVE-2025-10771
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2.
LOW 2.1EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-502
- Affected
- jeecg/jimureport
- Source
- cna@vuldb.com
References
- https://github.com/jeecgboot/jimureport/issues/4117Exploit, Issue Tracking, Third Party Advisory
- https://github.com/jeecgboot/jimureport/issues/4117#issue-3391268438Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.325127Permissions Required, VDB Entry
- https://vuldb.com/?id.325127Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.649778Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.