Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-27103


DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, a bypass for the patch for CVE-2024-55953 allows authenticated users to read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available.


Published

2025-03-13T17:15:36.930

Last Modified

2025-03-28T19:55:11.007

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-89
    CWE-862
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dataease dataease < 2.10.6 Yes

References