CVE-2025-27103
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Published Mar 13, 2025
Updated: Mar 28, 2025
CWE ID 862
CWE ID 89
Summary
CVE-2025-27103 is a new vulnerability affecting the open-source business intelligence tool, DataEase. Despite the previous patch for CVE-2024-55953, authenticated users can still bypass the security measure and read or deserialize arbitrary files via the background JDBC connection. This issue, which has been resolved in version 2.10.6, poses a significant risk to data privacy and integrity. Unfortunately, no workarounds have been identified for organizations still using affected versions.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Data Ease
Affected Vendors
- Dataease