Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-14335

39
FAUCET Score

CVE-2018-14335 is an information disclosure vulnerability affecting H2 Database version 1.4.197. It allows an authenticated attacker to read sensitive files outside of their intended permissions by exploiting insecure handling of symlinks within the backup function. Rated 6.5 Medium on CVSS, this vulnerability has a low attack complexity and can lead to high confidentiality impact. While not observed in active exploitation (KEV), public exploit code is available via ExploitDB, though there is minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
1.4.197CPE matchmatch criteria
cpe:2.3:a:h2database:h2:1.4.197:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

6.5MEDIUM

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
13.39%
Probability of exploitation in next 30 days
EPSS Percentile
96.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
ExploitDB: EDB-45105 · Jul 30, 2018
This CVE's current EPSS score of 0.1339 is in the 99th percentile among its peer group of 21,954 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (8)

redhatpatch availablevia redhat_api
Product: Red Hat Data Grid 7.3.3Fixed in: h2
View patch
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 13 (Queens)Fixed in: opendaylight
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 8 (Liberty)Fixed in: opendaylight
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 9 (Mitaka)Fixed in: opendaylight
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 6Fixed in: h2
redhatend of lifevia redhat_api
Product: Red Hat JBoss Enterprise Application Platform 7Fixed in: h2
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 12 (Pike)Fixed in: opendaylight
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 10 (Newton)Fixed in: opendaylight

Vendor Advisories (1)

redhatCVE-2018-14335Moderate

h2: Information Exposure due to insecure handling of permissions in the backup

Jul 23, 2018

References

access.redhat.com / errata/RHSA-2020:0727
gist.github.com / owodelta/9714faf9a86435cef5a99d4930eaee20
ExploitThird Party Advisory
lists.apache.org / thread.html/582d4165de6507b0be82d5a6f9a1ce392ec43a00c9fed32bacf7fe1e%40%3Cuser.ignite.apache.org%3E
security.netapp.com / advisory/ntap-20240726-0003
exploit-db.com / exploits/45105
ExploitThird Party AdvisoryVDB Entry