PT-2019-9267 · Postgresql · Pgpooladmin

Fotios Rogkotis

·

Publicado

2019-01-09

·

Atualizado

2019-10-03

·

CVE-2018-16203

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PgpoolAdmin versions 4.0 and earlier
Description The issue allows remote attackers to bypass login authentication and obtain administrative privileges of the PostgreSQL database. The exact vectors used for the attack are not specified.
Recommendations For PgpoolAdmin versions 4.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2018-16203

Produtos afetados

Pgpooladmin