Количество 9
Количество 9

CVE-2022-26520
** DISPUTED ** In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties.

CVE-2022-26520
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties

CVE-2022-26520
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties
CVE-2022-26520
In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or pro ...

SUSE-SU-2022:2655-1
Security update for postgresql-jdbc

SUSE-FU-2022:2794-1
Feature update for ongres-scram, ongres-stringprep, postgresql-jdbc

ROS-20240815-11
Уязвимость postgresql-jdbc
GHSA-727h-hrw8-jg8q
Path traversal in org.postgresql:postgresql

BDU:2024-06539
Уязвимость драйвера JDBC pgjdbc для подключения Java-программ к базе данных PostgreSQL, связанная с недостаточной проверкой входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2022-26520 ** DISPUTED ** In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
![]() | CVE-2022-26520 In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
![]() | CVE-2022-26520 In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or properties) can call java.util.logging.FileHandler to write to arbitrary files through the loggerFile and loggerLevel connection properties. An example situation is that an attacker could create an executable JSP file under a Tomcat web root. NOTE: the vendor's position is that there is no pgjdbc vulnerability; instead, it is a vulnerability for any application to use the pgjdbc driver with untrusted connection properties | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
CVE-2022-26520 In pgjdbc before 42.3.3, an attacker (who controls the jdbc URL or pro ... | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
![]() | SUSE-SU-2022:2655-1 Security update for postgresql-jdbc | 1% Низкий | почти 3 года назад | |
![]() | SUSE-FU-2022:2794-1 Feature update for ongres-scram, ongres-stringprep, postgresql-jdbc | 1% Низкий | почти 3 года назад | |
![]() | ROS-20240815-11 Уязвимость postgresql-jdbc | CVSS3: 9.8 | 1% Низкий | 11 месяцев назад |
GHSA-727h-hrw8-jg8q Path traversal in org.postgresql:postgresql | 1% Низкий | больше 3 лет назад | ||
![]() | BDU:2024-06539 Уязвимость драйвера JDBC pgjdbc для подключения Java-программ к базе данных PostgreSQL, связанная с недостаточной проверкой входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу