CVE-2017-15097
published 2018-07-27CVE-2017-15097: Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these…
PriorityP429medium6.7CVSS 3.0
AVLACLPRHUINSUCHIHAH
EPSS
0.54%
41.7th percentile
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | postgresql_init_script | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_server_eus | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv3.06.7MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4fwh-62fj-p4ww: Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL
ghsa_unreviewed·2022-05-24
CVE-2017-15097 [HIGH] CWE-59 GHSA-4fwh-62fj-p4ww: Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
Red Hat
postgresql: Start scripts permit database administrator to modify root-owned files
vendor_redhat·2017-12-07·CVSS 6.5
CVE-2017-15097 [MEDIUM] CWE-59 postgresql: Start scripts permit database administrator to modify root-owned files
postgresql: Start scripts permit database administrator to modify root-owned files
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.
Statement: Red Hat Enterprise Linux 6 is now in Production 3 Phase of the support and maintenance life cycle. This has been rated as having Moderate security impact and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Lin
No detection rules found.
No public exploits indexed.
http://www.securitytracker.com/id/1039983https://access.redhat.com/errata/RHSA-2017:3402https://access.redhat.com/errata/RHSA-2017:3403https://access.redhat.com/errata/RHSA-2017:3404https://access.redhat.com/errata/RHSA-2017:3405https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15097http://www.securitytracker.com/id/1039983https://access.redhat.com/errata/RHSA-2017:3402https://access.redhat.com/errata/RHSA-2017:3403https://access.redhat.com/errata/RHSA-2017:3404https://access.redhat.com/errata/RHSA-2017:3405https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-15097
2018-07-27
Published