GobyVuls/Smartbi DB2 JDBC Arbitrary Code Execution Vulnerability.md

1.1 KiB

Smartbi DB2 JDBC Arbitrary Code Execution Vulnerability

Vulnerability Smartbi DB2 JDBC Arbitrary Code Execution Vulnerability
Chinese name Smartbi DB2 JDBC 任意代码执行漏洞
CVSS core 9.8
FOFA Query (click to view the results directly) [(body="gcfutil = jsloader.resolve('smartbi.gcf.gcfutil')")
Number of assets affected 291
Description Smartbi is a business intelligence BI software launched by Smart Software, which meets the development stage of BI products.
Impact There is an unauthorized access background interface vulnerability between Smartbi V7 and V10.5.8. Combining DB2 JDBC exploitation and bypassing defense checks can lead to JNDI injection vulnerabilities, executing arbitrary code, and obtaining server privileges.