CVE-2018-10054 describes a critical remote code execution vulnerability in H2 database version 1.4.197, affecting products like Datomic, where the CREATE ALIAS function can execute arbitrary Java code. With a CVSS score of 8.8 (HIGH), this vulnerability is easily exploitable over the network with low privileges, allowing for complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, a Metasploit module exists for exploitation, and its high EPSS score indicates a significant likelihood of future exploitation, despite a lack of public discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.9.5697CPE matchmatch criteria | cpe:2.3:a:cognitect:datomic:*:*:*:*:*:*:*:* | ||
1.4.197CPE matchmatch criteria | cpe:2.3:a:h2database:h2:1.4.197:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.