PT-2023-10828 · Blue Yonder · Postgraas Server
Published
2023-07-18
·
Updated
2024-05-17
·
CVE-2018-25088
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Blue Yonder postgraas server versions up to 2.0.0b2
Description
A critical issue was found in the PostgreSQL Backend Handler component, specifically in the
create pg connection/create postgres db function of the postgraas server/backends/postgres cluster/postgres cluster driver.py file. This issue leads to sql injection.Recommendations
To address this issue, upgrade to version 2.0.0. As a temporary workaround, consider restricting access to the vulnerable
postgraas server component to minimize the risk of exploitation.Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Postgraas Server