PT-2026-102462 · Apache · Apache Karaf
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Karaf (affected versions not specified)
Description
Missing authorization in the
jdbc and jms shell command scopes allows authenticated users, including those with only the viewer role, to execute any jdbc:* and jms:* commands. This occurs because the command guard SecuredSessionFactoryImpl allows commands that lack a matching Access Control List (ACL) rule. Specifically, the jdbc:ds-create command allows the storage of an unvalidated, attacker-controlled JDBC URL into a pax-jdbc-config factory configuration, which is then converted into a live DataSource. Since some JDBC drivers execute code or SQL based on URL parameters, a user with viewer privileges can achieve arbitrary code execution, bypassing the administrative role requirements typically protecting shell:exec.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Karaf