PT-2024-10316 · Microsoft · Azure Database For Postgresql Flexible Server

Martin Wrona

+1

·

Published

2024-11-12

·

Updated

2025-01-07

·

CVE-2024-49042

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Azure Database for PostgreSQL Flexible Server (affected versions not specified)
Description The issue is related to an elevation of privilege vulnerability in Azure Database for PostgreSQL Flexible Server. It is associated with a failure to properly clean up data at the management level. Exploitation of this issue could allow a remote attacker to execute arbitrary code and elevate their privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-00763
CVE-2024-49042

Affected Products

Azure Database For Postgresql Flexible Server