CVE-2025-24974
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 13, 2025
Updated: Mar 21, 2025
CWE ID 862
CWE ID 89
Summary
CVE-2025-24974 is a vulnerability affecting the open source business intelligence and data visualization tool, DataEase. Before version 2.10.6, authenticated users were able to read and deserialize arbitrary files through the background JDBC connection. This issue poses a significant risk, as it allows unauthorized access to sensitive data. The vulnerability has been addressed in version 2.10.6, but as of now, there are no known workarounds for affected users until they upgrade to the latest version.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Data Ease
Affected Vendors
- Dataease