SECURITY: Data sent during IMPORT/EXPORT FROM/INTO LOCAL FILE statements may be obtained by eavesdroppers

Details

Detail name Value
Changelog Number 16130
Type Bug
Status Resolved
Affected Versions Exasol 7.1.1
Fix Versions Exasol 7.1.17
Resolution Date 2023-01-12

Description

Due to an issue in Exasol's JDBC driver, an attacker eavesdropping on the network connection between the client and Exasol may be able to obtain the data sent on this connection during IMPORT/EXPORT FROM/INTO LOCAL FILE statements.

Note: This issue does NOT affect the remaining JDBC client communication to/from Exasol (e.g. regular sessions, queries, etc.).