7.8
CVSSv3

CVE-2022-45868

Published: 23/11/2022 Updated: 11/04/2024
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 0

Vulnerability Summary

The web-based admin console in H2 Database Engine prior to 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the user to specify the password in cleartext for the web admin console. Consequently, a local user (or an attacker that has obtained local access through some means) would be able to discover the password by listing processes and their arguments. NOTE: the vendor states "This is not a vulnerability of H2 Console ... Passwords should never be passed on the command line and every qualified DBA or system administrator is expected to know that." Nonetheless, the issue was fixed in 2.2.220.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

h2database h2

Github Repositories

CHALLENGE Contexto: Recientemente varios hospitales de la zona han recibido una serie de ataques informáticos y se ha propuesto renovar el sistema de control de citas en el hospital AccWe, ya que es lo que mas tiempo lleva sin actualizarse Los desarrolladores han salvado parte del proyecto anterior y lo han limpiado para evitar posibles errores, actualizando sobretodo l

Demo app Swagger URL: localhost:8080/swagger-ui/indexhtml TODO: Update Spring Boot Starter Parent 314 ASAP to fix vulnerabilities from dependencies: CVE-2023-33264 CVE-2023-26119 CVE-2022-45868 CVE-2022-1471 More info: mvnrepositorycom/artifact/orgspringframeworkboot/spring-boot-starter-parent/314

These are the following environment variables that must be set for the application to run properly: SIMPLE_PING_APP_PING_CMD SIMPLE_PING_APP_HOSTS SIMPLE_PING_APP_IMCP_DELAY SIMPLE_PING_APP_TCPIP_DELAY SIMPLE_PING_APP_TRACERT_DELAY SIMPLE_PING_APP_TRACERT_CMD SIMPLE_PING_APP_REPORT_URL SIMPLE_PING_APP_TCPIP_RESPONSE_TIME_LIMIT SIMPLE_PING_APP_REPORT_LOG_FILE In order t

Listado de fotos por álbum

Introducción Microservicio en SpringBoot con 3 endpoints: albums-and-photos/db?useType=[arrayList|treeSet] -> Elimina la información que hubiera en memoria Realiza una carga de datos de la web Devuelve la lista de álbumes junto con las fotos que contiene a partir de la información almacenada en base de datos El parámetro useType es