GHSA-77xx-rxvh-q682

    Dashboard / Vulnerabilities / GHSA-77xx-rxvh-q682

    GHSA-77xx-rxvh-q682

    Published: 6 Oct 2022Last Modified: 8 Nov 2023

    Summary: HyperSQL DataBase vulnerable to remote code execution when processing untrusted input

    Details: Those using `java.sql.Statement` or `java.sql.PreparedStatement` in hsqldb (HyperSQL DataBase) to process untrusted input may be vulnerable to a remote code execution attack. By default it is allowed to call any static method of any Java class in the classpath resulting in code execution. The issue can be prevented by updating to 2.7.1 or by setting the system property "hsqldb.method_class_names" to classes which are allowed to be called. For example, `System.setProperty("hsqldb.method_class_names", "abc")` or Java argument `-Dhsqldb.method_class_names="abc"` can be used. From version 2.7.1 all classes by default are not accessible except those in `java.lang.Math` and need to be manually enabled.

    Affected packages

    Package

    Name: org.hsqldb:hsqldb

    Purl: pkg:maven/org.hsqldb/hsqldb

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.7.1

    Affected versions

    1.8.0.10

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-77xx-rxvh-q682 | CVE-DB