Intel

AIKIDO-2025-10231

aws-advanced-jdbc-wrapper is vulnerable to Insecure Default Variable Initialization

Insecure Default Variable Initialization Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

JAVAaws-advanced-jdbc-wrapper
2.3.2 - 2.5.5
Fixed in 2.5.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable due to an unsafe default value for the SSL Insecure parameter, which disables server certificate verification during SAML assertion workflows. This can expose applications to man-in-the-middle attacks. The parameter should default to false to ensure secure SSL connections.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

aws-advanced-jdbc-wrapper is vulnerable to Insecure Default Variable Initialization in versions 2.3.2 - 2.5.5.

How to fix this

Upgrade the software.amazon.jdbc:aws-advanced-jdbc-wrapper library to the patch version and/or set sslInsecure to false.