#VU126338 Improper input validation in DataEase - CVE-2025-48999
Published: April 16, 2026
DataEase
DataEase
Description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper input validation in the Redshift data source JDBC connection parameter handling when constructing a JDBC connection string from user-supplied host input. A remote user can supply crafted JDBC connection parameters to execute arbitrary code.
The issue is a bypass of a previous fix and relies on malicious JDBC parameters being concatenated into the constructed connection string.