All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-25767.json"