PostgreSQL.Database.Core.Server.non-libpq.Client.Policy.Bypass
Description
This indicates an attack attempt to exploit a Security Policy Bypass vulnerability in PostgreSQL database
server.
The vulnerability is due to improper authentication of user in the libpq module. A remote attacker may be able to exploit this to access/modify data through bypassing the authentication filter via crafted packets.
Affected Products
PostgreSQL PostgreSQL 9.2.x prior to 9.2.22
PostgreSQL PostgreSQL 9.3.x prior to 9.3.18
PostgreSQL PostgreSQL 9.4.x prior to 9.4.13
PostgreSQL PostgreSQL 9.5.x prior to 9.5.8
PostgreSQL PostgreSQL 9.6.x prior to 9.6.4
Impact
Security Bypass: Remote attackers can bypass security checks of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor
https://www.postgresql.org/about/news/1772/
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |
Version Updates
Date | Version | Detail |
---|---|---|
2019-06-05 | 14.626 | Severity:low:critical |