CVE-2024-55551
CVSS 3.1 Score 8.3 of 10 (high)
Details
Published Mar 19, 2025
Updated: Apr 2, 2025
CWE ID 471
CWE ID 94
Summary
CVE-2024-55551 is a newly discovered vulnerability affecting Exasol JDBC driver versions prior to 24.2.1 (released on December 10, 2024). This issue allows attackers to inject malicious parameters into the JDBC URL, leading to JNDI injection during the connection process. Successful exploitation of this vulnerability can result in remote code execution, potentially compromising the affected database and associated systems. It is recommended that users update to the latest version of the Exasol JDBC driver to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.