7.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
7.5 High
AI Score
Confidence
Low
0.006 Low
EPSS
Percentile
79.0%
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the βstandard_conforming_stringsβ option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 12 | all | libpgjava | <Β 42.5.4-1 | libpgjava_42.5.4-1_all.deb |
Debian | 11 | all | libpgjava | <Β 42.2.15-1+deb11u1 | libpgjava_42.2.15-1+deb11u1_all.deb |
Debian | 999 | all | libpgjava | <Β 42.7.3-1 | libpgjava_42.7.3-1_all.deb |
Debian | 13 | all | libpgjava | <Β 42.7.3-1 | libpgjava_42.7.3-1_all.deb |