Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
jeecgboot JimuReport DB2 JDBC testConnection deserialization
Vulnerability Description
A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Vulnerability Type
可信数据的反序列化
Vulnerability Title
JimuReport 代码问题漏洞
Vulnerability Description
JimuReport是中国JEECG开源的一个免费报表工具。 JimuReport 2.1.2及之前版本存在代码问题漏洞,该漏洞源于组件DB2 JDBC Handler中文件/drag/onlDragDataSource/testConnection对参数clientRerouteServerListJNDIName的操作不当,可能导致远程反序列化攻击。
CVSS Information
N/A
Vulnerability Type
N/A