CVE-2025-64428

CRITICAL

Dataease < 2.10.17 - Injection

Title source: rule
STIX 2.1

Description

Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. The vulnerability has been fixed in version 2.10.17.

Scores

CVSS v3 9.8
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-74
Status published
Products (1)
dataease/dataease < 2.10.17
Published Nov 20, 2025
Tracked Since Feb 18, 2026