It was discovered that HSQLDB could allow the execution of arbitrary
public static Java methods. A carefully crafted odb file opened in Base could execute arbitrary commands with the
permissions of the user running (CVE-2007-4575)

It was discovered that HSQLDB did not have a password set on the 'sa'
user. If HSQLDB has been configured as a service, a remote attacker
who could connect to the HSQLDB port (tcp 9001) could execute
arbitrary SQL commands. (CVE-2003-0845)

Note that in Scientific Linux 5, HSQLDB is not enabled as a service by
default, and needs manual configuration in order to work as a service.

Update the affected packages.

High / CVSS Base Score : 9.3
Public Exploit Available : true

