CVE-2022-40145 | Apache Karaf up to 4.3.7/4.4.1 JDBC JNDI URL doCreateDatasource injection
A vulnerability was found in Apache Karaf up to 4.3.7/4.4.1. It has been classified as critical. This affects the function doCreateDatasource of the component JDBC JNDI URL Handler. The manipulation leads to injection.
This vulnerability is uniquely identified as CVE-2022-40145. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.