CVE-2025-24974

MEDIUM

DataEase < 2.10.6 - Authenticated Arbitrary File Read and Deserialization via JDBC Connection

Title source: llm
STIX 2.1

Description

DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, authenticated users can read and deserialize arbitrary files through the background JDBC connection. The vulnerability has been fixed in v2.10.6. No known workarounds are available.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0036
EPSS Percentile 28.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-862 CWE-89
Status published
Products (1)
dataease/dataease < 2.10.6
Published Mar 13, 2025
Tracked Since Feb 18, 2026