Total vulnerabilities in the database
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
Software | From | Fixed in |
---|---|---|
h2database / h2 | 1.4.197 | 1.4.197.x |
cognitect / datomic | - | 0.9.5697 |
![]() |
- | 0.9.5697 |