Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:27944
HistoryNov 20, 2020 - 9:42 a.m.

Malicious Code Execution

2020-11-2009:42:45
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
33
postgresql
vulnerability
malicious code
sql functions
superuser
data confidentiality
data integrity
system availability

EPSS

0.026

Percentile

90.3%

postgresql is vulnerable to malicious code execution. An attacker having permission to create non-temporary objects in at least one schema can execute arbitrary SQL functions under the identity of a superuser. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.