CVE-2025-24974

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 13, 2025
Updated: Mar 21, 2025
CWE ID 862
CWE ID 89

Summary

CVE-2025-24974 is a vulnerability affecting the open source business intelligence and data visualization tool, DataEase. Before version 2.10.6, authenticated users were able to read and deserialize arbitrary files through the background JDBC connection. This issue poses a significant risk, as it allows unauthorized access to sensitive data. The vulnerability has been addressed in version 2.10.6, but as of now, there are no known workarounds for affected users until they upgrade to the latest version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share