Veritas is aware of three recently published vulnerabilities for the H2 Database Engine:
- CVE-2021-23463 XML External Entity (XXE) Injection Vulnerability
- CVE-2021-42392 JNDI driver name Remote Code Execution Vulnerability
- CVE-2022-23221 JDBC URL Remote Code Execution Vulnerability
Veritas engineers have assessed the potential exploitability in our Veritas products. We have determined that there are currently no Veritas products that expose the vulnerable H2 Database Engine features, therefore we do not believe that any of our products are impacted by these vulnerabilities at this time. We value your trust in Veritas products.
THE SECURITY ADVISORY IS PROVIDED "AS IS" AND ALL EXPRESS OR IMPLIED CONDITIONS, REPRESENTATIONS AND WARRANTIES, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT, ARE DISCLAIMED, EXCEPT TO THE EXTENT THAT SUCH DISCLAIMERS ARE HELD TO BE LEGALLY INVALID. VERITAS TECHNOLOGIES LLC SHALL NOT BE LIABLE FOR INCIDENTAL OR CONSEQUENTIAL DAMAGES IN CONNECTION WITH THE FURNISHING, PERFORMANCE, OR USE OF THIS DOCUMENTATION. THE INFORMATION CONTAINED IN THIS DOCUMENTATION IS SUBJECT TO CHANGE WITHOUT NOTICE.
Veritas Technologies LLC
2625 Augustine Drive
Santa Clara, CA 95054