---
title: "CVE-2022-45868\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2022-45868?format=md
keywords: index, follow
---

# CVE-2022-45868

Publication date 23 November 2022

Last updated 4 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**7.8 · High**

[Score breakdown](https://ubuntu.com/security/CVE-2022-45868?format=md#impact-score)

Toggle side navigation

## Description

The web-based admin console in H2 Database Engine before 2.2.220 can be
started via the CLI with the argument -webAdminPassword, which allows the
user to specify the password in cleartext for the web admin console.
Consequently, a local user (or an attacker that has obtained local access
through some means) would be able to discover the password by listing
processes and their arguments. NOTE: the vendor states "This is not a
vulnerability of H2 Console ... Passwords should never be passed on the
command line and every qualified DBA or system administrator is expected to
know that." Nonetheless, the issue was fixed in 2.2.220.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2022-45868?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| h2database | 24.04 LTS noble | Not affected |
| 23.10 mantic | Ignored end of life, was needs-triage |
| 23.04 lunar | Ignored end of life, was needs-triage |
| 22.10 kinetic | Ignored end of life, was needs-triage |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Not in release |
| jameica-h2database | 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not in release |
| 20.04 LTS focal | Not in release |
| 18.04 LTS bionic | Not in release |
| 16.04 LTS xenial | Not in release |
| 14.04 LTS trusty | Not in release |
| mediathekview | 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 20.04 LTS focal | Not affected |
| 18.04 LTS bionic | Not affected |
| 16.04 LTS xenial | Not affected |
| 14.04 LTS trusty | Ignored end of standard support |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [rodrigo-zaiden](https://launchpad.net/~rodrigo-zaiden)

the argument was added in version 1.4.198, so, versions
prior to that are not affected.
mediathekview includes h2database version 1.4.197.
jameica-h2database is based on version 1.4.197.
upstream states that the argument is used in H2 console
that is a tool for developers.

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

7.8 · High

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Unchanged |
  | Confidentiality impact | High |
  | Integrity impact | High |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 7.8 · High |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45868)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2022-45868)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2022-45868)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2022-45868)

### Other references

* <https://github.com/h2database/h2database/blob/96832bf5a97cdc0adc1f2066ed61c54990d66ab5/h2/src/main/org/h2/server/web/WebServer.java#L346-L347>
* <https://sites.google.com/sonatype.com/vulnerabilities/sonatype-2022-6243>
* <https://www.cve.org/CVERecord?id=CVE-2022-45868>
