Untrusted search path in snowflake-jdbc - CVE-2025-24789
Published: June 27, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to usage of an untrusted search path. A local user with write access to a directory in the %PATH% can escalate their privileges to the user that runs the vulnerable JDBC Driver version, when EXTERNALBROWSER authentication method is used on Windows.
Affected software
IBM Cloud Pak for Watson AIOps
How to mitigate CVE-2025-24789
IBM Cloud Pak for Watson AIOps - update to 4.10.0