Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.

Libreoffice HSQLdb Data Exposure

OESA-2026-1489
Summary

A security update is available for Libreoffice to prevent an attacker from accessing sensitive data. This issue allows an attacker to trick a user into opening a malicious file, which can then write sensitive information to a location controlled by the attacker. Users should update to the latest version of Libreoffice to protect against this type of attack.

What to do
  • Update hsqldb to version 2.4.0-6.oe2203sp4.
Affected software
VendorProductAffected versionsFix available
– hsqldb <= 2.4.0-6.oe2203sp4 2.4.0-6.oe2203sp4
Original title
hsqldb security update
Original description
HSQLdb is a relational database engine written in JavaTM , with a JDBC driver, supporting a subset of ANSI-92 SQL. It offers a small (about 100k), fast database engine which offers both in memory and disk based tables. Embedded and server modes are available. Additionally, it includes tools such as a minimal web server, in-memory query and management tools (can be run as applets or servlets, too) and a number of demonstration examples. Downloaded code should be regarded as being of production quality. The product is currently being used as a database and persistence engine in many Open Source Software projects and even in commercial projects and products! In it&amp;apos;s current version it is extremely stable and reliable. It is best known for its small size, ability to execute completely in memory and its speed. Yet it is a completely functional relational database management system that is completely free under the Modified BSD License. Yes, that&amp;apos;s right, completely free of cost or restrictions!

Security Fix(es):

A flaw was found in the Libreoffice package. An attacker can craft an odb containing a &quot;database/script&quot; file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.(CVE-2023-1183)
Published: 6 Mar 2026 · Updated: 6 Mar 2026 · First seen: 6 Mar 2026