ZeroHour

CVE-2017-7547

CVSS 3.0
8.8 high
EPSS
6%p92
Published
()
Modified
Description

PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to authorization flaw allowing remote authenticated attackers to retrieve passwords from the user mappings defined by the foreign server owners without actually having the privileges to do so.

Vendors
postgresql
Products
postgresql
Weakness
CWE-522
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news