An issue was discovered in Exasol JDBC driver before 24.2.1...
Vulnerability Description
An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-55551
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.blackhat.com/eu-24/briefings/schedule/index.html#a-novel-attack-surface-java-authentication-and-authorization-service-jaas-42179
- https://docs.exasol.com/db/latest/connect_exasol/drivers/jdbc.htm
- https://gist.github.com/azraelxuemo/9565ec9219e0c3e9afd5474904c39d0f
- https://docs.exasol.com/db/7.1/release_notes_drivers_jdbc/24.2.1.htm
Affected Vendor
Exasol
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.