Showing 2 vulnerabilities on this page for Amazon Redshift JDBC Driver

Signals CISA KEV Ransomware Nuclei
Amazon vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Remote Code Execution via Unsafe Class Loading in Amazon Redshift JDBC Driver

An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load and execute arbitrary classes when processing JDBC connection URL parameters. An actor who can influence the connection URL could potentially execute code in the application context, provided a suitable class is available on the application's classpath. To mitigate this issue, users should upgrade to version 2.2.2 or later.

CWE-470May 8, 2026
CVSS9.2v4.0EPSS0.573%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

SQL Injection in the Amazon Redshift JDBC Driver affecting v2.1.0.31

A SQL injection in the Amazon Redshift JDBC Driver in v2.1.0.31 allows a user to gain escalated privileges via the getSchemas, getTables, or getColumns Metadata APIs. Users should upgrade to the driver version 2.1.0.32 or revert to driver version 2.1.0.30.

CWE-89Dec 24, 2024
CVSS8.6v4.0EPSS0.591%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX