Aller au contenu

Fiche vulnérabilité

CVE-2025-10771 : faille critique jeecg jimureport (CVSS 9.8)

Description

A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
21 sept. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • jeecg jimureport

Références

Rechercher une autre vulnérabilité dans la base CVE