vendor:
H2 Database
by:
owodelta
6.5
CVSS
MEDIUM
Information Disclosure
200
CWE
Product Name: H2 Database
Affected Version From: all versions
Affected Version To: all versions
Patch Exists: YES
Related CWE: CVE-2018-14335
CPE: 2.3:a:h2database:h2_database:1.4.197
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2018
H2 Database 1.4.197 – Information Disclosure
Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.
Mitigation:
Ensure that the permissions of the backup function are properly configured and that the backup files are stored in a secure location.