Lucene search

K
debiancveDebian Security Bug TrackerDEBIANCVE:CVE-2012-1618
HistoryOct 06, 2012 - 10:55 p.m.

CVE-2012-1618

2012-10-0622:55:01
Debian Security Bug Tracker
security-tracker.debian.org
7

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.0%

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the β€œstandard_conforming_strings” option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.5 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

79.0%