SECURITY: Data sent during IMPORT/EXPORT FROM/INTO LOCAL FILE statements may be obtained by eavesdroppers
Details
| Detail name | Value |
|---|---|
| Changelog Number | 16130 |
| Type | Bug |
| Status | Resolved |
| Affected Versions | Exasol 7.1.1 |
| Fix Versions | Exasol 7.1.17 |
| Resolution Date | 2023-01-12 |
Description
Due to an issue in Exasol's JDBC driver, an attacker eavesdropping on the network connection between the client and Exasol may be able to obtain the data sent on this connection during IMPORT/EXPORT FROM/INTO LOCAL FILE statements.
Note: This issue does NOT affect the remaining JDBC client communication to/from Exasol (e.g. regular sessions, queries, etc.).