PT-2015-6377 · Actian · Actian Matrix

Published

2015-06-13

·

Updated

2016-12-06

·

CVE-2015-3993

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Actian Matrix versions 5.1.x through 5.1.2.4 Actian Matrix versions 5.2.x through 5.2.0.1
Description The issue allows remote authenticated users to bypass intended write-access restrictions. This is achieved by referencing a table to execute an UPDATE statement.
Recommendations For Actian Matrix versions 5.1.x through 5.1.2.4, update to a version that includes the necessary security fixes to restrict unauthorized access to tables. For Actian Matrix versions 5.2.x through 5.2.0.1, apply configuration changes to enforce strict access controls and prevent unauthorized execution of UPDATE statements.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-3993

Affected Products

Actian Matrix