PT-2019-9267 · Postgresql · Pgpooladmin

Fotios Rogkotis

·

Published

2019-01-09

·

Updated

2019-10-03

·

CVE-2018-16203

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PgpoolAdmin versions 4.0 and earlier
Description The issue allows remote attackers to bypass login authentication and obtain administrative privileges of the PostgreSQL database. The exact vectors used for the attack are not specified.
Recommendations For PgpoolAdmin versions 4.0 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2018-16203

Affected Products

Pgpooladmin