Files
CVEs-PoC/2025/CVE-2025-5662.md
T
2025-09-29 21:09:30 +02:00

977 B

CVE-2025-5662

Description

A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3.46.0.7. This vulnerability allows remote code execution (RCE) due to improper validation of JDBC connection parameters when using a Key-Value format. The vulnerability is present in the MySQL JDBC Driver version 8.0.19 and JDK version 8u112. The issue is resolved in version 3.46.0.8.

POC

Reference

No PoCs from references.

Github