DataEase DB2 JNDI Vulnerability Severity: High CVE ID: CVE-2025-64428 Package: - (Maven) Affected versions: <= 2.10.16 Patched versions: 2.10.17 Impact A blacklist was added in the patch for v2.10.14. However, JNDI injection remains possible via the iiop, corbaname, and iiopname schemes. Proof of Concept / Exploitation Example URLs: Patches The vulnerability has been fixed in v2.10.17. Workarounds It is recommended to upgrade the version to v2.10.17. References If you have any questions or comments about this advisory: Open an issue in GitHub link Email: weifit2cloud.com