j2ee.pointbase.txt...

- AV AC AU C I A
发布: 2004-01-19
修订: 2025-04-13

Attached is an exploit that crashes the Pointbase 4.6 database server that comes with the J2EE reference implementation. It is caused by fact that the Pointbase installation coming with j2ee/ri 1.4. is not equipped with an appropriate security manager, thus giving all jars implicitly all permissions. These unlimited permissions can be exploited by an attacker using jdbc to crash the jvm running the pointbase server. Further exploitations possible are information disclosure and remote command injection.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息