6.5
CVSSv3

CVE-2017-15099

Published: 22/11/2017 Updated: 28/08/2018
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x prior to 10.1, 9.6.x prior to 9.6.6, and 9.5.x prior to 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

postgresql postgresql 9.5.3

postgresql postgresql 9.5.4

postgresql postgresql 9.6.1

postgresql postgresql 9.6.2

postgresql postgresql 9.5

postgresql postgresql 9.5.7

postgresql postgresql 9.5.8

postgresql postgresql 9.6.5

postgresql postgresql 10.0

postgresql postgresql 9.5.1

postgresql postgresql 9.5.2

postgresql postgresql 9.5.9

postgresql postgresql 9.6

postgresql postgresql 9.5.5

postgresql postgresql 9.5.6

postgresql postgresql 9.6.3

postgresql postgresql 9.6.4

debian debian linux 9.0

Vendor Advisories

Synopsis Important: rh-postgresql96-postgresql security update Type/Severity Security Advisory: Important Topic An update for rh-postgresql96-postgresql is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Synopsis Important: rh-postgresql95-postgresql security update Type/Severity Security Advisory: Important Topic An update for rh-postgresql95-postgresql is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Privilege escalation flaws were found in the initialization scripts of PostgreSQL A remote attacker with access to the postgres user account could use these flaws to obtain root access on the server machine(CVE-2017-12172) INSERT ON CONFLICT DO UPDATE commands in PostgreSQL disclose table contents that the invoker lacks privilege to read Th ...
INSERT ON CONFLICT DO UPDATE commands in PostgreSQL 10x before 101, 96x before 966, and 95x before 9510 disclose table contents that the invoker lacks privilege to read These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges Exploits bypass row level security policies and ...
An access restriction bypass vulnerability has been discovered in PostgreSQL, the "INSERT ON CONFLICT DO UPDATE" would not check to see if the executing user had permission to perform a "SELECT" on the index performing the conflicting check Additionally, in a table with row-level security enabled, the "INSERT ON CONFLICT DO UPDATE" would n ...
For more information about PostgreSQL versioning, please visit the versioning page ...