VendorsApacheiotdball versions
Vulnerabilities

Apache Software Foundation IoTDB

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

20CVEs
CVE-2020-1952
An issue was found in Apache IoTDB .9.0 to 0.9.1 and 0.8.0 to 0.8.2. When starting IoTDB, the JMX port 31999 is exposed with no certification.Then, clients could execute code remotely.
Published 2020-04-27 · Modified
9.8EPSS 0.027
CVE-2023-46226
Apache IoTDB: Remote Code Execution (RCE) risk via the UDF
Published 2024-01-15 · Modified
9.8EPSS 0.019
CVE-2024-24780
Apache IoTDB: Remote Code Execution with untrusted URI of User-defined function
Published 2025-05-14 · Analyzed
9.8EPSS 0.013
CVE-2023-24831
Apache IoTDB grafana-connector Login Bypass Vulnerability
Published 2023-04-17 · Modified
9.8EPSS 0.012
CVE-2023-51656
Apache IoTDB: Unsafe deserialize map in Sync Tool
Published 2023-12-21 · Modified
9.8EPSS 0.010
CVE-2026-24014
Apache IoTDB: Path Traversal in DataNode Internal RPC Trigger JAR Upload Allows Arbitrary File Write
Published 2026-07-06 · Analyzed
9.8EPSS 0.007
CVE-2026-24713
Apache IoTDB: JEXL Expression Injection Vulnerability
Published 2026-03-09 · Analyzed
9.8EPSS 0.007
CVE-2026-24015
Apache IoTDB: Insecure Default Configuration Vulnerability
Published 2026-03-09 · Analyzed
9.8EPSS 0.006
CVE-2026-24013
Apache IoTDB: Authentication Bypass via Forged SessionID in Thrift RPC
Published 2026-07-06 · Analyzed
9.1EPSS 0.006
CVE-2022-38369
Login check vulnerability by session Id
Published 2022-09-05 · Modified
8.8EPSS 0.013
CVE-2023-24829
Apache IoTDB Workbench: apache/iotdb-web-workbench: forge the JWTToken to access workbench
Published 2023-01-31 · Modified
8.8EPSS 0.012
CVE-2020-25649
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Published 2020-12-03 · Modified
7.5EPSS 0.178
CVE-2022-43766
Apache IoTDB prior to 0.13.3 allows DoS
Published 2022-10-26 · Modified
7.5EPSS 0.014
CVE-2022-38370
No authorization of DatabaseConnectController in grafana-connector.
Published 2022-09-05 · Modified
7.5EPSS 0.013
CVE-2023-24830
Apache IoTDB Workbench: apache/iotdb-web-workbench: create a user without authorization
Published 2023-01-30 · Modified
7.5EPSS 0.013
CVE-2026-24012
Apache IoTDB: Denial of Service via Resource Exhaustion in Aggregation Query
Published 2026-07-06 · Analyzed
7.5EPSS 0.007
CVE-2025-26864
Apache IoTDB: Exposure of Sensitive Information in IoTDB OpenID Authentication
Published 2025-05-14 · Analyzed
7.5EPSS 0.007
CVE-2025-26795
Apache IoTDB JDBC driver: Exposure of Sensitive Information in IoTDB JDBC driver
Published 2025-05-14 · Analyzed
7.5EPSS 0.007
CVE-2025-48392
Apache IoTDB: DoS Vulnerability
Published 2025-09-24 · Modified
7.5EPSS 0.006
CVE-2025-48459
Apache IoTDB: Deserialization of untrusted Data
Published 2025-09-24 · Modified
5.3EPSS 0.005