Description

A deserialization vulnerability exists in the H2O-3 REST API (POST /99/ImportSQLTable) that affects all versions up to 3.46.0.7. This vulnerability allows remote code execution (RCE) due to improper validation of JDBC connection parameters when using a Key-Value format. The vulnerability is present in the MySQL JDBC Driver version 8.0.19 and JDK version 8u112. The issue is resolved in version 3.46.0.8.

INFO

Published Date :

2025-09-02T11:14:52.744Z

Last Modified :

2025-09-02T15:50:21.879Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2025-5662 vulnerability.

Vendors Products
H2oai
  • H2o-3
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-5662.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact