docs.exasol.com
https://docs.exasol.com/db/7.1/release_notes_drivers_jdbc/24.2.1.htm CVE-2024-55551
HIGH
Record summary
CVE-2024-55551 has a selected CVSS score of 8.3 (high).
Description
An issue was discovered in Exasol JDBC driver before 24.2.1 (2024-12-10). Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote code execution.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 19, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
JDBC driverBrowse Exasol / JDBC driverDefault status: unaffected | CVE List | Before 24.2.1 | affected |
References
5docs.exasol.com
https://docs.exasol.com/db/latest/connect_exasol/drivers/jdbc.htm gist.github.com
https://gist.github.com/azraelxuemo/9565ec9219e0c3e9afd5474904c39d0f nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-55551 blackhat.com
https://www.blackhat.com/eu-24/briefings/schedule/index.html