Lucene search

K
redosRedosROS-20221013-03
HistoryOct 13, 2022 - 12:00 a.m.

ROS-20221013-03

2022-10-1300:00:00
redos.red-soft.ru
13
postgresql
remote exploit
privilege escalation
database management system

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

61.5%

A vulnerability in the PostgreSQL database management system is related to errors when using OR commands
extensions. Exploitation of the vulnerability could allow an attacker acting remotely to escalate their
privileges and replace arbitrary objects in the database

OSVersionArchitecturePackageVersionFilename
redos7.3x86_64postgresql-1c<= 14.5-1UNKNOWN

8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

0.002 Low

EPSS

Percentile

61.5%