PT-2016-1648 · Postgresql · Postgresql

·

CVE-2016-2193

·

Published

2016-03-31

·

Updated

2025-02-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions PostgreSQL versions prior to 9.5.2
Description The issue is related to errors in security settings, allowing a remote attacker to bypass existing access restrictions by leveraging a session that performs queries as more than one role. This is due to the improper maintenance of row-security status in cached plans.
Recommendations For versions prior to 9.5.2, update to version 9.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to roles that perform queries as more than one role to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00974
CVE-2016-2193
MGASA-2016-0136
OPENSUSE-SU-2024:10273-1

Affected Products

Postgresql