ZeroHour

CVE-2017-7546

CVSS 3.0
9.8 critical
EPSS
62%p99
Published
()
Modified
Description

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.

Vendors
postgresqldebian
Products
postgresql, debian linux
Weakness
CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news