CVE-2023-39016: Bbossgroups Bboss

Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.

bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.

Affected products

Published 2023-07-28. Last modified 2026-06-17.