PT-2026-22063 · Unknown+3 · Mchange-Commons-Java+3
CVSS v4.0
8.9
High
| Vector | AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
c3p0 versions prior to 0.12.0
Description
A flaw in the JDBC connection pooling library allows a remote attacker to achieve arbitrary code execution on the application's
CLASSPATH. The issue exists because several ConnectionPoolDataSource implementations use a property called userOverridesAsString that was maintained as a hex-encoded Java serialized object. An attacker can manipulate this property using maliciously crafted Java-serialized objects or javax.naming.Reference instances to trigger deserialization. This risk is increased by a dependency on mchange-commons-java, which provides ungated support for remote factoryClassLocation values. By combining these, an attacker can force the application to download and execute malicious code from a remote location. JNDI (Java Naming and Directory Interface) is a Java API that allows applications to discover and look up data and objects via a name.Recommendations
Update c3p0 to version 0.12.0 or above.
Exploit
Fix
Code Injection
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Ubuntu
C3P0
Mchange-Commons-Java