← Vulnerability feed

Vulnerability record · CVE-2018-14335 · published 24 July 2018

CVE-2018-14335: H2database h2 link following vulnerability

H2database · H2

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

6.5 CVSS 3.1 Medium EPSS 13% · top 3.7% CWE-59 · Link followingCWE-276 · Incorrect default permissions
6.5CVSS 3.1 base score, v2 4.0
13%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-14335 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23221H2 Console JDBC URL argument injection enables remote code executionH2 Console before 2.1.210 accepts a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, …EPSS 65%analysed9.8CVE-2021-42392H2 database JNDI lookup flaw allows unauthenticated remote code executionThe org.h2.util.JdbcUtils.getConnection method in the H2 database accepts a driver class name and database URL from the caller. An attacker can suppl…EPSS 83%analysed9.1CVE-2021-23463H2database h2 xml external entity (xxe) vulnerabilityThe package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML cl…EPSS 2.7%8.8CVE-2018-10054Cognitect datomic improper input validation vulnerabilityH2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.…EPSS 34%7.8CVE-2022-45868H2database h2 cleartext storage of sensitive data vulnerabilityThe web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the use…EPSS 0.31%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed7.8CVE-2015-5287ABRT abrt-hook-ccpp symlink privilege escalationThe abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a l…KEVEPSS 5.0%analysed7.8CVE-2026-41091Microsoft Defender link following allows local privilege elevationMicrosoft Defender's malware protection engine resolves links improperly before accessing files, a link-following flaw (CWE-59). A local attacker wit…KEVEPSS 0.44%analysed

Source: NIST National Vulnerability Database (record CVE-2018-14335), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.