DataEase DB2 SSRF Vulnerability Package Maven: io.dataease (Maven) Affected Versions <= 2.10.14 Patched Versions 2.10.15 Severity High CVE ID CVE-2025-64163 Description Overview In the fix for LDAP injection in v2.10.12, the vendor added a blacklist to filter ldap:// and ldaps://. However, omission of protection for the dns:// protocol results in this SSRF vulnerability. Exploit Payload: First set up a DNS log platform with yakit. Insert the payload into the JDBC connection string field and click "Get Schema". Impact Server-Side Request Forgery (SSRF) Patches The vulnerability has been fixed in v2.10.15. Workarounds It is recommended to upgrade the version to v2.10.15. References Open an issue in https://github.com/dataease/dataease Email us at weilanfit2cloud.com