CVE-2017-15098
HIGH
8,1
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: none
Availability: high
MEDIUM
5,5
Source: [email protected]
Access Vector: network
Access Complexity: low
Authentication: single
Confidentiality: partial
Integrity: none
Availability: partial
Description
AI Translation Available
Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0077
Percentile
0,7th
Updated
EPSS Score Trend (Last 91 Days)
200
Exposure of Sensitive Information to an Unauthorized Actor
DraftCommon Consequences
Security Scopes Affected:
Confidentiality
Potential Impacts:
Read Application Data
Applicable Platforms
Technologies:
Mobile, Not Technology-Specific, Web Based
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.15:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.18:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.8:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.12:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.6.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.12:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.6.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.13:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.19:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.17:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.6.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.6.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.11:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.14:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Debian Linux by Debian
CPE Identifier
View Detailed Analysis
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.6.2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.9:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.1:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.13:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.16:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.4.14:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.4:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.5.3:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Postgresql by Postgresql
CPE Identifier
View Detailed Analysis
cpe:2.3:a:postgresql:postgresql:9.3.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://access.redhat.com/errata/RHSA-2018:2511
https://access.redhat.com/errata/RHSA-2018:2566
https://www.debian.org/security/2017/dsa-4027
https://www.debian.org/security/2017/dsa-4028
https://www.postgresql.org/about/news/1801/
https://www.postgresql.org/support/security/
http://www.securityfocus.com/bid/101781
http://www.securitytracker.com/id/1039752
https://access.redhat.com/errata/RHSA-2018:2511
https://access.redhat.com/errata/RHSA-2018:2566
https://www.debian.org/security/2017/dsa-4027
https://www.debian.org/security/2017/dsa-4028
https://www.postgresql.org/about/news/1801/
https://www.postgresql.org/support/security/
http://www.securityfocus.com/bid/101781
http://www.securitytracker.com/id/1039752