CVE-2012-1618

UnknownEPSS 2.94%

Last modified

CVE-2012-1618 is a vulnerability of currently unknown severity. Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.. EPSS estimates a 2.94% chance of exploitation in the next 30 days.

Description

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

Metrics

EPSS Probability
2.94%

85.4th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
PostgresqlPostgresql9.1
PostgresqlPostgresql Jdbc Driver8.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-1618?
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.
How severe is CVE-2012-1618?
Severity scoring for CVE-2012-1618 is pending analysis. The EPSS model estimates a 2.94% probability of exploitation in the next 30 days.
How do I fix CVE-2012-1618?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-1618?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST