CVE-2018-10054

H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cognitect:datomic:*:*:*:*:*:*:*:*
cpe:2.3:a:h2database:h2:1.4.197:*:*:*:*:*:*:*

History

19 Jul 2024, 14:15

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20240719-0003/ -

Information

Published : 2018-04-11 20:29

Updated : 2024-08-05 08:15


NVD link : CVE-2018-10054

Mitre link : CVE-2018-10054

CVE.ORG link : CVE-2018-10054


JSON object : View

Products Affected

cognitect

  • datomic

h2database

  • h2
CWE
CWE-20

Improper Input Validation