Critical severity9.8NVD Advisory· Published May 1, 2022· Updated Jun 17, 2026
CVE-2022-25767
CVE-2022-25767
Description
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.bstek.ureport:ureport2-consoleMaven | <= 2.2.9 | — |
Affected products
3- cpe:2.3:a:ureport2_project:ureport2:*:*:*:*:*:*:*:*
- com.bstek.ureport/ureport2-consoledescription
Patches
Vulnerability mechanics
References
4- github.com/JinYiTong/CVE-Req/blob/main/ureport2/ureport2-console.mdnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-w39x-chvm-pj3cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25767ghsaADVISORY
- snyk.io/vuln/SNYK-JAVA-COMBSTEKUREPORT-2322018nvdThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.