Lucene search

K
ibmIBM565C98E17BAB791BFD12CB6910DB2160173B321DB556E36239E115FA14DCC1F7
HistoryDec 03, 2021 - 8:39 p.m.

Security Bulletin: EDB PostreSQL with IBM, EDB Postgres Advanced Server with IBM, IBM Data Management Platform (Enterprise, Standard) are vulnerable to an SQL Injection (CVE-2021-23214)

2021-12-0320:39:18
www.ibm.com
18
edb postresql
ibm
edb postgres advanced server
sql injection
cve-2021-23214
data management platform
vulnerability
postgresql
edb
ibm data management

EPSS

0.002

Percentile

57.2%

Summary

EDB PostreSQL with IBM and EDB Postgres Advanced Server with IBM are vulnerable to an SQL Injection

Vulnerability Details

CVEID:CVE-2021-23214
**DESCRIPTION:**PostgreSQL is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements when the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, which could allow the attacker to view, add, modify or delete information in the back-end database.
CVSS Base score: 8.1
CVSS Temporal Score: See: https://exchange.xforce.ibmcloud.com/vulnerabilities/213379 for the current score.
CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)

Affected Products and Versions

Affected Product(s) Version(s)

EDB PostgreSQL with IBM

EDB Postgres Advanced Server with IBM

| 13.1

IBM Data Management Platform for EDB Enterprise

IBM Data Management Platform for EDB Standard

| 2.0.0 SR1 (includes EDB v12)

IBM Data Management Platform for EDB Enterprise

| 1.0.0

Remediation/Fixes

Upgrade to latest version of EDB Postgres Advanced Server and PostgreSQL.

<https://www.enterprisedb.com/software-downloads-postgres&gt;

  • If you have IBM Data Management Platform for EDB Enterprise, please download EDB Postgres Advanced Server.
  • If you have IBM Data Management Platform for EDB Standard, please download PostgreSQL.

Workarounds and Mitigations

None