Skip to main content

Vendor/product archive

h2database / h2 CVEs

Beta · best-effort

6 CVEs tagged to h2database / h22 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2022-45868

Published Nov 23, 2022

The web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in c…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-23463

Published Dec 10, 2021

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives p…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-14335

Published Jul 24, 2018

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlin…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-10054

Published Apr 11, 2018

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position i…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1