H2 Console before 2.1.210 allows remote attackers to execute arbitrary code via a jdbc:h2:mem JDBC URL containing the IGNOREUNKNOWNSETTINGS=TRUE;FORBID_CREATION=FALSE;INIT=RUNSCRIPT substring, a different vulnerability than CVE-2021-42392.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "1.9.0"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "10.0"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "11.0"
}
]
},
{
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.0"
}
]
}
]
}{
"cpe": "cpe:2.3:a:h2database:h2:*:*:*:*:*:*:*:*",
"source": [
"CPE_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "1.1.100"
},
{
"fixed": "2.0.206"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2022-23221.json"
"2026-04-12T02:50:33Z"
[
{
"deprecated": false,
"signature_type": "Line",
"digest": {
"line_hashes": [
"272810656635025776199681441561795810929",
"245591617129835704064380813555882338322",
"306412481140467524166442158358643941576",
"171885524935467376214112428467882639055",
"152693961729231181337235161892963699712",
"11128620713700209481157025108943595581",
"229492663452310778701433303382354959535",
"280099107836224806134227223277985234471"
],
"threshold": 0.9
},
"target": {
"file": "h2/src/main/org/h2/engine/Constants.java"
},
"source": "https://github.com/h2database/h2database/commit/3d957a0aeb509c5976a3489e7867ecbb121280f4",
"signature_version": "v1",
"id": "CVE-2022-23221-007ddf6d"
},
{
"deprecated": false,
"signature_type": "Function",
"digest": {
"function_hash": "315764262499076112425286640966310751787",
"length": 3343.0
},
"target": {
"file": "h2/src/tools/org/h2/build/Build.java",
"function": "javadocImpl"
},
"source": "https://github.com/h2database/h2database/commit/3d957a0aeb509c5976a3489e7867ecbb121280f4",
"signature_version": "v1",
"id": "CVE-2022-23221-2e529f64"
},
{
"deprecated": false,
"signature_type": "Line",
"digest": {
"line_hashes": [
"306343085252609351417168749835012023517",
"24484998409013538956641732370396970576",
"62200468007006360416996496122250431518",
"3323092461967229912768068215658008818"
],
"threshold": 0.9
},
"target": {
"file": "h2/src/tools/org/h2/build/Build.java"
},
"source": "https://github.com/h2database/h2database/commit/3d957a0aeb509c5976a3489e7867ecbb121280f4",
"signature_version": "v1",
"id": "CVE-2022-23221-7128582e"
}
]