SQL injection in DataEase - #VU151951

 

SQL injection in DataEase - #VU151951

Published: September 24, 2026


Vulnerability identifier: #VU151951
CSH Severity: Low
CVSS v4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-89
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper neutralization of special elements used in an SQL command in the getTableFiledSql method of CalciteProvider.java when handling table metadata requests. A remote user can submit a crafted table identifier to disclose sensitive information.

Exploitation requires access to the target datasource and a table whose name contains the crafted identifier.


Affected software

DataEase

Remediation

Install security update from vendor's website.

DataEase - addressed in versions 2.10.27, 3.1.0

External References

Related Security Bulletins