Description
A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3.46.0.7. This vulnerability allows remote code execution (RCE) due to improper validation of JDBC connection parameters when using a Key-Value format. The vulnerability is present in the MySQL JDBC Driver version 8.0.19 and JDK version 8u112. The issue is resolved in version 3.46.0.8.
INFO
Published Date :
2025-09-02T11:14:52.744Z
Last Modified :
2025-09-02T15:50:21.879Z
Source :
@huntr_ai
AFFECTED PRODUCTS
The following products are affected by CVE-2025-5662 vulnerability.
| Vendors | Products |
|---|---|
| H2oai |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-5662.
CVSS Vulnerability Scoring System
Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact