7.5 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
0.006 Low
EPSS
Percentile
79.0%
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with
a PostgreSQL server with the βstandard_conforming_stringsβ option enabled,
such as the default configuration of PostgreSQL 9.1, does not properly
escape unspecified JDBC statement parameters, which allows remote attackers
to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that
the upstream developer planned to dispute this issue, but an official
dispute has not been posted as of 20121005.
Author | Note |
---|---|
sbeattie | according to comment 11 in novell bug 754273 (below), this was fixed in 8.2-504) |