← Vulnerability feed

Vulnerability record · CVE-2021-23463 · published 10 December 2021

CVE-2021-23463: H2database h2 xml external entity (xxe) vulnerability

H2database · H2

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

9.1 CVSS 3.1 Critical EPSS 2.7% · top 14.7% CWE-611 · XML external entity (XXE)
9.1CVSS 3.1 base score, v2 6.4
2.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML class object, when it receives parsed string data from org.h2.jdbc.JdbcResultSet.getSQLXML() method. If it executes the getSource() method when the parameter is DOMSource.class it will trigger the vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23463 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23221H2 Console JDBC URL argument injection enables remote code executionH2 Console before 2.1.210 accepts a jdbc:h2:mem JDBC URL containing the IGNORE_UNKNOWN_SETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, …EPSS 65%analysed9.8CVE-2021-42392H2 database JNDI lookup flaw allows unauthenticated remote code executionThe org.h2.util.JdbcUtils.getConnection method in the H2 database accepts a driver class name and database URL from the caller. An attacker can suppl…EPSS 83%analysed8.8CVE-2018-10054Cognitect datomic improper input validation vulnerabilityH2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code.…EPSS 34%7.8CVE-2022-45868H2database h2 cleartext storage of sensitive data vulnerabilityThe web-based admin console in H2 Database Engine before 2.2.220 can be started via the CLI with the argument -webAdminPassword, which allows the use…EPSS 0.31%6.5CVE-2018-14335H2database h2 link following vulnerabilityAn issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of t…EPSS 13%9.8CVE-2025-58360GeoServer WMS GetMap XXE allows unauthenticated file read and SSRFGeoServer versions 2.26.0 through 2.26.2 and before 2.25.6 accept XML input at the /geoserver/wms GetMap endpoint without sufficiently restricting ex…KEVEPSS 61%analysed9.8CVE-2025-2776SysAid On-Prem unauthenticated XXE in Server URL processingSysAid On-Prem versions up to 23.3.40 process the Server URL without restricting XML external entities, so an unauthenticated attacker can supply cra…KEVEPSS 64%analysed7.5CVE-2025-2775SysAid On-Prem unauthenticated XXE in Checkin processingSysAid On-Prem versions up to 23.3.40 process Checkin XML without restricting external entities, so an unauthenticated attacker can supply a crafted …KEVEPSS 43%analysed

Source: NIST National Vulnerability Database (record CVE-2021-23463), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.