#VU126337 Improper input validation in DataEase - CVE-2025-46566
Published: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in the redshift JDBC connection handling when processing a user-supplied JDBC URL. A remote user can send a specially crafted request containing a malicious JDBC connection string to execute arbitrary code.
The issue can be triggered through the /de2api/datasource/getSchema endpoint.