CVE-2016-6656
Last modified
CVE-2016-6656 is a vulnerability of currently unknown severity. An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into the system. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into the system. In order to exploit this vulnerability the user must have superuser 'gpadmin' access to the system or have been granted GPHDFS protocol permissions in order to create a GPHDFS external table.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Greenplum | <= 4.3.9.1 |
References
- https://pivotal.io/security/cve-2016-6656Mitigation, Vendor Advisory
- https://pivotal.io/security/cve-2016-6656Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6656?
How severe is CVE-2016-6656?
How do I fix CVE-2016-6656?
Are you affected by CVE-2016-6656?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
