Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2022-45136— Apache Jena SDB allows arbitrary deserialisation via JDBC

EPSS 1.96% · P84
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2022-45136

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Jena SDB allows arbitrary deserialisation via JDBC
Source: NVD (National Vulnerability Database)
Vulnerability Description
Apache Jena SDB 3.17.0 and earlier is vulnerable to a JDBC Deserialisation attack if the attacker is able to control the JDBC URL used or cause the underlying database server to return malicious data. The mySQL JDBC driver in particular is known to be vulnerable to this class of attack. As a result an application using Apache Jena SDB can be subject to RCE when connected to a malicious database server. Apache Jena SDB has been EOL since December 2020 and users should migrate to alternative options e.g. Apache Jena TDB 2.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
可信数据的反序列化
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache Jena 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache Jena是美国阿帕奇(Apache)基金会的一个Java语义网框架。用于构建语义Web和链接数据应用程序。 Apache Jena SDB 3.17.0及之前版本存在代码问题漏洞,该漏洞源于容易受到JDBC反序列化攻击,如果攻击者能够控制所使用的JDBC URL或导致底层数据库服务器返回恶意数据,当连接到恶意数据库服务器时,使用应用程序可能会受到RCE攻击。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache Jena SDB unspecified ~ 3.17.0 -

II. Public POCs for CVE-2022-45136

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-45136

登录查看更多情报信息。

Same Patch Batch · Apache Software Foundation · 2022-11-14 · 4 CVEs total

CVE-2022-27949Apache Airflow prior to 2.3.1 may include sensitive values in rendered template
CVE-2022-40127Apache Airflow <2.4.0 has an RCE in a bash example
CVE-2022-45378Apache SOAP allows unauthenticated users to potentially invoke arbitrary code

IV. Related Vulnerabilities

V. Comments for CVE-2022-45136

No comments yet


Leave a comment