CVE-2018-14335 EXPLOIT
6.5
MEDIUM · CVSS 3.1 · EPSS 13.4% (pctl 96)
Patch early
A public exploit exists.
Description
An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
Scoring
| CVSS | 6.5 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 13.39% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-59 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-07-24 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| h2database | h2 |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | H2 Database 1.4.197 - Information Disclosure | 2018-07-30 |
References
- https://access.redhat.com/errata/RHSA-2020:0727
- https://gist.github.com/owodelta/9714faf9a86435cef5a99d4930eaee20
- https://lists.apache.org/thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e%40%3Cuser.ignite.apache.org%3E
- https://security.netapp.com/advisory/ntap-20240726-0003/
- https://www.exploit-db.com/exploits/45105/
- https://access.redhat.com/errata/RHSA-2020:0727
- https://gist.github.com/owodelta/9714faf9a86435cef5a99d4930eaee20
- https://lists.apache.org/thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e%40%3Cuser.ignite.apache.org%3E
- https://security.netapp.com/advisory/ntap-20240726-0003/
- https://www.exploit-db.com/exploits/45105/
→ the Explorer · watch your stack · NVD