CVE-2024-55551 Details
Description
An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
A JNDI injection vulnerability has been identified in the Exasol JDBC driver, specifically in versions prior to 24.2.1. This vulnerability allows attackers to inject malicious parameters into the JDBC URL, which the driver may then execute when connecting to the database. The exploitation of this vulnerability could lead to remote code execution.
Users are advised to update to Exasol JDBC driver version 24.2.1 or later, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-471 | Modification of Assumed-Immutable Data (MAID) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| exasol jdbc driver | < 24.2.1 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Sep 26, 2025 | Modified Analysis | [email protected] |
| Aug 27, 2025 | CVE Modified | CISA-ADP |
| Jul 8, 2025 | Initial Analysis | [email protected] |
| Apr 2, 2025 | CVE Modified | [email protected] |
| Mar 25, 2025 | CVE Modified | [email protected] |
| Mar 19, 2025 | CVE Modified | CISA-ADP |
| Mar 19, 2025 | New CVE Received | [email protected] |