Other nomination
Exploiting HSQLDB
An Apache and Tomcat path-normalisation difference lets /..;/ in a URL slip past the F5 BIG-IP TMUI proxy rules and reach the hidden hsqldb servlet unauthenticated. Default HSQLDB credentials then allow arbitrary SQL, and its CALL statement invokes an F5 static method that evaluates Jython, giving unauthenticated remote code execution (CVE-2020-5902).
Record
- Researcher
- Mikhail Klyuchnikov and @m1ke_n1
- Published by
- PT SWARM
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Mikhail Klyuchnikov and @m1ke_n1, first published at the original source. Preserved copies are kept so the citation survives its host.