GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.27.0 of the GeoServer DB2 DataStore Extension, an administrator can perform a JNDI attack through specially crafted DB2 jdbc url leading to to Remote Code Execution (RCE). Version 2.27.0 fixes the issue.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HOsgeo Geoserver
APPOsgeo< 2.27.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEDeserialization
Related vulnerabilities
CVE-2024-34711CRITICAL9.3PL ✓same product
GeoServer: XXE umożliwiające skanowanie sieci wewnętrznych (SSRF)
CVE-2025-30220CRITICAL9.9PL ✓same product
XXE w GeoTools/GeoServer/GeoNetwork — podatność XML External Entity
CVE-2023-25157CRITICAL9.8PL ✓same product
SQL Injection w GeoServer poprzez filtry OGC/CQL (WFS, WMS, WCS)
CVE-2025-52465HIGH7.2same product
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26...
CVE-2024-29198HIGH7.5same product
GeoServer is an open source software server written in Java that allows users to share and edit geospatial dat...