CVE-2025-27103

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 13, 2025
Updated: Mar 28, 2025
CWE ID 862
CWE ID 89

Summary

CVE-2025-27103 is a new vulnerability affecting the open-source business intelligence tool, DataEase. Despite the previous patch for CVE-2024-55953, authenticated users can still bypass the security measure and read or deserialize arbitrary files via the background JDBC connection. This issue, which has been resolved in version 2.10.6, poses a significant risk to data privacy and integrity. Unfortunately, no workarounds have been identified for organizations still using affected versions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share