Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-42392

The org.h2.util.JdbcUtils.getConnection method of the H2 database takes as parameters the class name of the driver and URL of the database. An attacker may pass a JNDI driver name and a URL leading to a LDAP or RMI servers, causing remote code execution. This can be exploited through various attack vectors, most notably through the H2 Console which leads to unauthenticated remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.917
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 10.0
References
Products affected by CVE-2021-42392
  • H2database » H2 » Version: 1.1.101
    cpe:2.3:a:h2database:h2:1.1.101
  • H2database » H2 » Version: 1.1.102
    cpe:2.3:a:h2database:h2:1.1.102
  • H2database » H2 » Version: 1.1.103
    cpe:2.3:a:h2database:h2:1.1.103
  • H2database » H2 » Version: 1.1.104
    cpe:2.3:a:h2database:h2:1.1.104
  • H2database » H2 » Version: 1.1.105
    cpe:2.3:a:h2database:h2:1.1.105
  • H2database » H2 » Version: 1.1.106
    cpe:2.3:a:h2database:h2:1.1.106
  • H2database » H2 » Version: 1.1.107
    cpe:2.3:a:h2database:h2:1.1.107
  • H2database » H2 » Version: 1.1.108
    cpe:2.3:a:h2database:h2:1.1.108
  • H2database » H2 » Version: 1.1.109
    cpe:2.3:a:h2database:h2:1.1.109
  • H2database » H2 » Version: 1.1.110
    cpe:2.3:a:h2database:h2:1.1.110
  • H2database » H2 » Version: 1.1.111
    cpe:2.3:a:h2database:h2:1.1.111
  • H2database » H2 » Version: 1.1.112
    cpe:2.3:a:h2database:h2:1.1.112
  • H2database » H2 » Version: 1.1.113
    cpe:2.3:a:h2database:h2:1.1.113
  • H2database » H2 » Version: 1.1.114
    cpe:2.3:a:h2database:h2:1.1.114
  • H2database » H2 » Version: 1.1.115
    cpe:2.3:a:h2database:h2:1.1.115
  • H2database » H2 » Version: 1.1.116
    cpe:2.3:a:h2database:h2:1.1.116
  • H2database » H2 » Version: 1.1.117
    cpe:2.3:a:h2database:h2:1.1.117
  • H2database » H2 » Version: 1.1.118
    cpe:2.3:a:h2database:h2:1.1.118
  • H2database » H2 » Version: 1.1.119
    cpe:2.3:a:h2database:h2:1.1.119
  • H2database » H2 » Version: 1.2.120
    cpe:2.3:a:h2database:h2:1.2.120
  • H2database » H2 » Version: 1.2.121
    cpe:2.3:a:h2database:h2:1.2.121
  • H2database » H2 » Version: 1.2.122
    cpe:2.3:a:h2database:h2:1.2.122
  • H2database » H2 » Version: 1.2.123
    cpe:2.3:a:h2database:h2:1.2.123
  • H2database » H2 » Version: 1.2.124
    cpe:2.3:a:h2database:h2:1.2.124
  • H2database » H2 » Version: 1.2.125
    cpe:2.3:a:h2database:h2:1.2.125
  • H2database » H2 » Version: 1.2.126
    cpe:2.3:a:h2database:h2:1.2.126
  • H2database » H2 » Version: 1.2.127
    cpe:2.3:a:h2database:h2:1.2.127
  • H2database » H2 » Version: 1.2.128
    cpe:2.3:a:h2database:h2:1.2.128
  • H2database » H2 » Version: 1.2.129
    cpe:2.3:a:h2database:h2:1.2.129
  • H2database » H2 » Version: 1.2.130
    cpe:2.3:a:h2database:h2:1.2.130
  • H2database » H2 » Version: 1.2.131
    cpe:2.3:a:h2database:h2:1.2.131
  • H2database » H2 » Version: 1.2.132
    cpe:2.3:a:h2database:h2:1.2.132
  • H2database » H2 » Version: 1.2.133
    cpe:2.3:a:h2database:h2:1.2.133
  • H2database » H2 » Version: 1.2.134
    cpe:2.3:a:h2database:h2:1.2.134
  • H2database » H2 » Version: 1.2.135
    cpe:2.3:a:h2database:h2:1.2.135
  • H2database » H2 » Version: 1.2.136
    cpe:2.3:a:h2database:h2:1.2.136
  • H2database » H2 » Version: 1.2.137
    cpe:2.3:a:h2database:h2:1.2.137
  • H2database » H2 » Version: 1.2.138
    cpe:2.3:a:h2database:h2:1.2.138
  • H2database » H2 » Version: 1.2.139
    cpe:2.3:a:h2database:h2:1.2.139
  • H2database » H2 » Version: 1.2.140
    cpe:2.3:a:h2database:h2:1.2.140
  • H2database » H2 » Version: 1.2.141
    cpe:2.3:a:h2database:h2:1.2.141
  • H2database » H2 » Version: 1.2.142
    cpe:2.3:a:h2database:h2:1.2.142
  • H2database » H2 » Version: 1.2.143
    cpe:2.3:a:h2database:h2:1.2.143
  • H2database » H2 » Version: 1.2.144
    cpe:2.3:a:h2database:h2:1.2.144
  • H2database » H2 » Version: 1.2.145
    cpe:2.3:a:h2database:h2:1.2.145
  • H2database » H2 » Version: 1.2.147
    cpe:2.3:a:h2database:h2:1.2.147
  • H2database » H2 » Version: 1.3.146
    cpe:2.3:a:h2database:h2:1.3.146
  • H2database » H2 » Version: 1.3.148
    cpe:2.3:a:h2database:h2:1.3.148
  • H2database » H2 » Version: 1.3.149
    cpe:2.3:a:h2database:h2:1.3.149
  • H2database » H2 » Version: 1.3.150
    cpe:2.3:a:h2database:h2:1.3.150
  • H2database » H2 » Version: 1.3.151
    cpe:2.3:a:h2database:h2:1.3.151
  • H2database » H2 » Version: 1.3.152
    cpe:2.3:a:h2database:h2:1.3.152
  • H2database » H2 » Version: 1.3.153
    cpe:2.3:a:h2database:h2:1.3.153
  • H2database » H2 » Version: 1.3.154
    cpe:2.3:a:h2database:h2:1.3.154
  • H2database » H2 » Version: 1.3.155
    cpe:2.3:a:h2database:h2:1.3.155
  • H2database » H2 » Version: 1.3.156
    cpe:2.3:a:h2database:h2:1.3.156
  • H2database » H2 » Version: 1.3.157
    cpe:2.3:a:h2database:h2:1.3.157
  • H2database » H2 » Version: 1.3.158
    cpe:2.3:a:h2database:h2:1.3.158
  • H2database » H2 » Version: 1.3.159
    cpe:2.3:a:h2database:h2:1.3.159
  • H2database » H2 » Version: 1.3.160
    cpe:2.3:a:h2database:h2:1.3.160
  • H2database » H2 » Version: 1.3.161
    cpe:2.3:a:h2database:h2:1.3.161
  • H2database » H2 » Version: 1.3.162
    cpe:2.3:a:h2database:h2:1.3.162
  • H2database » H2 » Version: 1.3.163
    cpe:2.3:a:h2database:h2:1.3.163
  • H2database » H2 » Version: 1.3.164
    cpe:2.3:a:h2database:h2:1.3.164
  • H2database » H2 » Version: 1.3.165
    cpe:2.3:a:h2database:h2:1.3.165
  • H2database » H2 » Version: 1.3.166
    cpe:2.3:a:h2database:h2:1.3.166
  • H2database » H2 » Version: 1.3.167
    cpe:2.3:a:h2database:h2:1.3.167
  • H2database » H2 » Version: 1.3.168
    cpe:2.3:a:h2database:h2:1.3.168
  • H2database » H2 » Version: 1.3.169
    cpe:2.3:a:h2database:h2:1.3.169
  • H2database » H2 » Version: 1.3.170
    cpe:2.3:a:h2database:h2:1.3.170
  • H2database » H2 » Version: 1.3.171
    cpe:2.3:a:h2database:h2:1.3.171
  • H2database » H2 » Version: 1.3.172
    cpe:2.3:a:h2database:h2:1.3.172
  • H2database » H2 » Version: 1.3.173
    cpe:2.3:a:h2database:h2:1.3.173
  • H2database » H2 » Version: 1.3.174
    cpe:2.3:a:h2database:h2:1.3.174
  • H2database » H2 » Version: 1.3.175
    cpe:2.3:a:h2database:h2:1.3.175
  • H2database » H2 » Version: 1.4.177
    cpe:2.3:a:h2database:h2:1.4.177
  • H2database » H2 » Version: 1.4.178
    cpe:2.3:a:h2database:h2:1.4.178
  • H2database » H2 » Version: 1.4.181
    cpe:2.3:a:h2database:h2:1.4.181
  • H2database » H2 » Version: 1.4.182
    cpe:2.3:a:h2database:h2:1.4.182
  • H2database » H2 » Version: 1.4.183
    cpe:2.3:a:h2database:h2:1.4.183
  • H2database » H2 » Version: 1.4.184
    cpe:2.3:a:h2database:h2:1.4.184
  • H2database » H2 » Version: 1.4.185
    cpe:2.3:a:h2database:h2:1.4.185
  • H2database » H2 » Version: 1.4.186
    cpe:2.3:a:h2database:h2:1.4.186
  • H2database » H2 » Version: 1.4.187
    cpe:2.3:a:h2database:h2:1.4.187
  • H2database » H2 » Version: 1.4.188
    cpe:2.3:a:h2database:h2:1.4.188
  • H2database » H2 » Version: 1.4.190
    cpe:2.3:a:h2database:h2:1.4.190
  • H2database » H2 » Version: 1.4.191
    cpe:2.3:a:h2database:h2:1.4.191
  • H2database » H2 » Version: 1.4.192
    cpe:2.3:a:h2database:h2:1.4.192
  • H2database » H2 » Version: 1.4.193
    cpe:2.3:a:h2database:h2:1.4.193
  • H2database » H2 » Version: 1.4.194
    cpe:2.3:a:h2database:h2:1.4.194
  • H2database » H2 » Version: 1.4.195
    cpe:2.3:a:h2database:h2:1.4.195
  • H2database » H2 » Version: 1.4.196
    cpe:2.3:a:h2database:h2:1.4.196
  • H2database » H2 » Version: 1.4.197
    cpe:2.3:a:h2database:h2:1.4.197
  • H2database » H2 » Version: 1.4.198
    cpe:2.3:a:h2database:h2:1.4.198
  • H2database » H2 » Version: 1.4.199
    cpe:2.3:a:h2database:h2:1.4.199
  • H2database » H2 » Version: 1.4.200
    cpe:2.3:a:h2database:h2:1.4.200
  • H2database » H2 » Version: 2.0.202
    cpe:2.3:a:h2database:h2:2.0.202
  • H2database » H2 » Version: 2.0.204
    cpe:2.3:a:h2database:h2:2.0.204
  • cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0
  • Debian » Debian Linux » Version: 10.0
    cpe:2.3:o:debian:debian_linux:10.0
  • Debian » Debian Linux » Version: 11.0
    cpe:2.3:o:debian:debian_linux:11.0
  • Debian » Debian Linux » Version: 9.0
    cpe:2.3:o:debian:debian_linux:9.0


Contact Us

Shodan ® - All rights reserved