CVE 5.3 MEDIUM

jeecgboot JimuReport DB2 JDBC testConnection deserialization_CVE-2025-10771

5.3 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

Description

A vulnerability was determined in jeecgboot JimuReport up to 2.1.2. Affected is an unknown function of the file /drag/onlDragDataSource/testConnection of the component DB2 JDBC Handler. Executing manipulation of the argument clientRerouteServerListJNDIName can lead to deserialization. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

Basic Information

ID CVE-2025-10771
Source VulDB
Published Sep 21, 2025 at 23:02

Affected Product

Vendor jeecgboot
Product JimuReport
Version 2.1.0
Affected Versions jeecgboot JimuReport 2.1.0
jeecgboot JimuReport 2.1.1
jeecgboot JimuReport 2.1.2

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.