Enterprisedb Postgres Advanced Server vulnerabilities
10 known vulnerabilities affecting enterprisedb/postgres_advanced_server.
Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2023-41118P3HIGHCVSS 8.8fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41118 [HIGH] CVE-2023-41118: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It may allow an authenticated user to bypass authorization requirements and access underlying implementation functions. When a superuser has configured file locations using CREATE DIRE
nvd
CVE-2023-41117P3CRITICALCVSS 9.8fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41117 [CRITICAL] CWE-427 CVE-2023-41117: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY DEFINER but are inadequately secured against search_path attacks.
nvd
CVE-2023-41119P3HIGHCVSS 8.8fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41119 [HIGH] CWE-269 CVE-2023-41119: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the function _dbms_aq_move_to_exception_queue that may be used to elevate a user's privileges to superuser. This function accepts the OID of a table, and then acces
nvd
CVE-2007-4639P4MEDIUMCVSS 6.5PoCv8.22007-08-31
CVE-2007-4639 [MEDIUM] CWE-824 CVE-2007-4639: EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occu
EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arbitrary code via a SELECT statement that invokes a pldbg_ function, as demonstrated by (1) pldbg_get_sta
nvd
CVE-2023-31043P3HIGHCVSS 7.5fixed in 10.23.33≥ 11.1.7, < 11.18.29+3 more2023-04-23
CVE-2023-31043 [HIGH] CWE-312 CVE-2023-31043: EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situatio
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and 14.6.0.
nvd
CVE-2023-41115P3MEDIUMCVSS 6.5fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41115 [MEDIUM] CVE-2023-41115: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTL_ENCODE, an authenticated user can read any large object, regardless of that user's permissions.
nvd
CVE-2023-41114P3MEDIUMCVSS 6.5fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41114 [MEDIUM] CVE-2023-41114: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the functions get_url_as_text and get_url_as_bytea that are publicly executable, thus permitting an authenticated user to read any file from the local filesystem or remot
nvd
CVE-2023-41120P3MEDIUMCVSS 6.5fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41120 [MEDIUM] CWE-668 CVE-2023-41120: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accumulated profiling data on a system-wide basis, regardless of that user's permissions.
nvd
CVE-2023-41113P4MEDIUMCVSS 4.3fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41113 [MEDIUM] CVE-2023-41113: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to to obtain information about whether certain files exist on disk, what errors if any occur when attempting to read them, and some limited informatio
nvd
CVE-2023-41116P4MEDIUMCVSS 4.3fixed in 11.21.32≥ 12.0.0, < 12.16.20+3 more2023-12-12
CVE-2023-41116 [MEDIUM] CVE-2023-41116: An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to refresh any materialized view, regardless of that user's permissions.
nvd