S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Apr 20, 2026

CVE-2025-49002 Scanner

CVE-2025-49002 Scanner - Remote Code Execution vulnerability in DataEase

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-49002
8.2
CVSShigh
Exploitable remotely over the internet · no authentication required.

DataEase is an open source business intelligence and data visualization tool. Versions prior to version 2.10.10 have a flaw in the patch for CVE-2025-32966 that allow the patch to be bypassed through case insensitivity because INIT and RUNSCRIPT are prohibited. The vulnerability has been fixed in v2.10.10. No known workarounds are available.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
dataeaseby dataease
< 2.10.10
Updated Aug 22, 2026View on NVD →
Detail

DataEase is an open-source business intelligence and data visualization platform that allows businesses to derive insights from diverse datasets. It is used by data analysts, IT departments, and project managers to make informed decisions based on data trends. The software supports dashboard and report creation, simplifying the representation of complex data visually. Organizations utilize DataEase to improve operational efficiencies and forecast trends by centralizing their data analytics efforts. Its open-source nature enables users to customize and extend functionalities as needed. DataEase is essential for businesses that prioritize data-driven decisions and enhanced reporting mechanisms.

The vulnerability detected in DataEase involves Remote Code Execution (RCE), allowing attackers to execute arbitrary code on the affected systems. This vulnerability arises due to improper validation and handling of user inputs, which leads to unauthorized actions within the server's environment. An attacker can exploit this flaw to gain control of the target system, presenting significant security risks. The vulnerability is severe as it typically requires little complexity to exploit and may cause substantial private data breaches. Its discovery underscores the continuous need for robust security protocols in software applications.

Technical details of the vulnerability involve improper case-insensitive handling of restricted H2 JDBC keywords in exposed DataEase instances. This weakness allows the attacker to send malformed HTTP POST requests to '/de2api/datasource/getSchema', extracting possible version hints for manual verification. Vulnerable endpoints fail to correctly sanitize parameters, enabling potential command execution on the server-side. Key indicators of exploitation include specific error and execution messages, such as exceptions calling functions and output from command executions. A successful attack could manifest if the vulnerable logic allows injection into the underlying database system.

The possible effects of exploiting this vulnerability include unauthorized data extraction, system hijacking, and disruption of business operations. Malicious entities may use this flaw to deploy ransomware, steal sensitive information, or establish persistent backdoors in the system. Organizations might suffer reputational damage alongside potential financial losses due to data breaches and non-compliance penalties. The execution of arbitrary commands could also lead to significant system downtime, affecting productivity and trust in the software. Mitigating this vulnerability is critical to protect not only the current data infrastructure but also to ensure future security.

REFERENCES

Solution Advice
  • Upgrade DataEase to version 2.10.10 or later to mitigate this vulnerability.
  • Restrict public access to management and API endpoints to limit exposure.
  • Regularly review exposed datasource-related interfaces for unauthorized access.
  • Implement network segmentation to compartmentalize sensitive areas of the application.
  • Conduct regular security audits and vulnerability assessments to detect similar issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.