CVE-2018-14335
H2 Database vulnerability analysis and mitigation

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.


SourceNVD

Related H2 Database vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2022-23221CRITICAL9.8
  • H2 DatabaseH2 Database
  • h2
NoYesJan 19, 2022
CVE-2021-42392CRITICAL9.8
  • H2 DatabaseH2 Database
  • com.h2database:h2
NoYesJan 10, 2022
CVE-2021-23463CRITICAL9.1
  • H2 DatabaseH2 Database
  • h2
NoYesDec 10, 2021
CVE-2022-45868HIGH7.8
  • H2 DatabaseH2 Database
  • h2
NoYesNov 23, 2022
CVE-2018-14335MEDIUM6.5
  • H2 DatabaseH2 Database
  • cpe:2.3:a:h2database:h2
NoYesJul 24, 2018

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management