Vulnerability

CVE-2018-14335
CVSS Score 4.0 medium

CVSS Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

CWE

CWE-276

[CVE-2018-14335] CWE-276: Incorrect Default Permissions

Description

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

See com.h2database/h2 package information