{"id":"CVE-2025-57773","summary":"Dataease DB2 Aspectweaver Deserialization Arbitrary File Write Vulnerability","details":"DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserialization attack, writing to various files. This vulnerability requires commons-collections 4.x and aspectjweaver-1.9.22.jar. The vulnerability has been fixed in version 2.10.12.","aliases":["GHSA-7r8j-6whv-4j5p"],"modified":"2026-08-12T15:16:50.923460Z","published":"2025-08-25T16:42:11.118Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-502","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57773.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57773.json"},{"type":"ADVISORY","url":"https://github.com/dataease/dataease/security/advisories/GHSA-7r8j-6whv-4j5p"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57773"},{"type":"FIX","url":"https://github.com/dataease/dataease/commit/8d04e92d44e1bac9284e9e64df5afd7f96d9373c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dataease/dataease","events":[{"introduced":"0"},{"fixed":"471bb6c7915646ac529ad3d6eb7662ab3166f994"},{"fixed":"8d04e92d44e1bac9284e9e64df5afd7f96d9373c"}],"database_specific":{"cpe":"cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.10.12"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.10.11","v2.10.10","v2.10.9","v2.10.8","v2.10.7","v2.10.6","v2.10.5","v2.10.4","v2.10.3","v2.10.2","v2.10.1","v2.10.0","v2.6.0","v2.3.0","v2.2.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-57773.json","vanir_signatures_modified":"2026-08-12T15:16:50Z","vanir_signatures":[{"source":"https://github.com/dataease/dataease/commit/8d04e92d44e1bac9284e9e64df5afd7f96d9373c","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java"},"deprecated":false,"digest":{"line_hashes":["27627074303964318882417323486351141630","97142947938543604819636395956544387028","40377677079330361915937831577686115372","77336536708444157242984543587993925663","226293177076656006578341433282022368995","226206026037102308028627587933519385431","250607821624320240021707600059182626213","229470453148276106606832723164433403161","36232095595880197123500286869313831397","230413827549299870676532268452966731911","155492726525485500818202825548485514582","172332398816939070015484972354472842339","156049878968505701786302864870376015886","234752437833024204454346191164166948173","22431626205809116371677207218277129167","315779692837072296632638343547471377864","198710618279807928606657002811482695105","93113150856017422359902813424132491185","266492111722602182777196203359326277604","121485586516182722547988612588894858163","205074086120764524306067702170957869882","297006563058528251310354195955554070247","255772802642667320584955123374174539061","197157854710776494115524897094803834866","119267620208540501041600515986837789320","67305898528663910404855856363929362337"],"threshold":0.9},"id":"CVE-2025-57773-39748a8a","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"185129634142087683166882728968280083370","length":1094},"id":"CVE-2025-57773-75e1ef67","signature_type":"Function","signature_version":"v1","source":"https://github.com/dataease/dataease/commit/8d04e92d44e1bac9284e9e64df5afd7f96d9373c","target":{"file":"core/core-backend/src/main/java/io/dataease/datasource/type/Db2.java","function":"getJdbc"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}