EDB PostreSQL with IBM and EDB Postgres Advanced Server with IBM are vulnerable to an SQL Injection
CVEID:CVE-2021-23214
**DESCRIPTION:**PostgreSQL is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements when the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213379 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Affected Product(s) | Version(s) |
---|
EDB PostgreSQL with IBM
EDB Postgres Advanced Server with IBM
| 13.1
IBM Data Management Platform for EDB Enterprise
IBM Data Management Platform for EDB Standard
| 2.0.0 SR1 (includes EDB v12)
IBM Data Management Platform for EDB Enterprise
| 1.0.0
Upgrade to latest version of EDB Postgres Advanced Server and PostgreSQL.
<https://www.enterprisedb.com/software-downloads-postgres>
None