Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly filter when establishing JDBC connections to Oracle, resulting in a risk of JNDI injection (Java Naming and Directory Interface injection). This issue is fixed in version 2.10.15.
{
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/64xxx/CVE-2025-64164.json",
"cwe_ids": [
"CWE-502"
]
}{
"cpe": "cpe:2.3:a:dataease:dataease:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.15"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}"2026-07-21T23:33:39Z"
[
{
"target": {
"file": "core/core-backend/src/main/java/io/dataease/datasource/type/Oracle.java"
},
"id": "CVE-2025-64164-93bff18a",
"digest": {
"line_hashes": [
"259953948377062273516977453137930248440",
"268422576957412557498942480132595803874",
"286302401596432558177322143996029946432",
"118856345715641815666051362113476234966",
"298112220770250500095987880054148860191",
"72226076396926608174044731529434890760",
"179242353202582750976305644674258681125",
"105102104323364711003633386545330221083",
"23557541642591024096404242953538893554",
"181496549562887174513840509782708746797",
"38007642714884842195257544857796548536",
"164505841738458278842585716469679007980"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/dataease/dataease/commit/7b68eb3dfccbbd12ec977e6320dbd3e32a7bbfe6"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-64164.json"