Apache Jena是美国阿帕奇(Apache)基金会的一个Java语义网框架。用于构建语义Web和链接数据应用程序。 Apache Jena SDB 3.17.0及之前版本存在代码问题漏洞,该漏洞源于容易受到JDBC反序列化攻击,如果攻击者能够控制所使用的JDBC URL或导致底层数据库服务器返回恶意数据,当连接到恶意数据库服务器时,使用应用程序可能会受到RCE攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Jena SDB | unspecified ~ 3.17.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-27949 | Apache Airflow prior to 2.3.1 may include sensitive values in rendered template | |
| CVE-2022-40127 | Apache Airflow <2.4.0 has an RCE in a bash example | |
| CVE-2022-45378 | Apache SOAP allows unauthenticated users to potentially invoke arbitrary code |
No comments yet