Логотип exploitDog
bind:"CVE-2017-15099"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2017-15099"

Количество 9

Количество 9

ubuntu логотип

CVE-2017-15099

около 8 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
EPSS: Средний
redhat логотип

CVE-2017-15099

около 8 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 3.1
EPSS: Средний
nvd логотип

CVE-2017-15099

около 8 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2017-15099

около 8 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10 ...

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-pcph-v7q2-77cx

больше 3 лет назад

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
EPSS: Средний
fstec логотип

BDU:2019-04099

больше 8 лет назад

Уязвимость реализации команды «INSERT ... ON CONFLICT DO UPDATE» системы управления базами данных PostgreSQL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
EPSS: Средний
suse-cvrf логотип

openSUSE-SU-2017:3425-1

почти 8 лет назад

Security update for postgresql96

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2017:3391-1

почти 8 лет назад

Security update for postgresql96

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2018:0529-1

почти 8 лет назад

Security update for postgresql95

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2017-15099

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
30%
Средний
около 8 лет назад
redhat логотип
CVE-2017-15099

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 3.1
30%
Средний
около 8 лет назад
nvd логотип
CVE-2017-15099

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
30%
Средний
около 8 лет назад
debian логотип
CVE-2017-15099

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10 ...

CVSS3: 6.5
30%
Средний
около 8 лет назад
github логотип
GHSA-pcph-v7q2-77cx

INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.

CVSS3: 6.5
30%
Средний
больше 3 лет назад
fstec логотип
BDU:2019-04099

Уязвимость реализации команды «INSERT ... ON CONFLICT DO UPDATE» системы управления базами данных PostgreSQL, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

CVSS3: 6.5
30%
Средний
больше 8 лет назад
suse-cvrf логотип
openSUSE-SU-2017:3425-1

Security update for postgresql96

почти 8 лет назад
suse-cvrf логотип
SUSE-SU-2017:3391-1

Security update for postgresql96

почти 8 лет назад
suse-cvrf логотип
openSUSE-SU-2018:0529-1

Security update for postgresql95

почти 8 лет назад

Уязвимостей на страницу