CVE-2016-6656
Last modified
CVE-2016-6656 is a vulnerability of currently unknown severity. An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into the system. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into the system. In order to exploit this vulnerability the user must have superuser 'gpadmin' access to the system or have been granted GPHDFS protocol permissions in order to create a GPHDFS external table.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Greenplum | <= 4.3.9.1 |
References
- https://pivotal.io/security/cve-2016-6656Mitigation, Vendor Advisory
- https://pivotal.io/security/cve-2016-6656Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-6656?
How severe is CVE-2016-6656?
How do I fix CVE-2016-6656?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-6650EMC RecoverPoint versions prior to 5.0 and EMC RecoverPoint …7.5
- CVE-2016-6651The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF)…
- CVE-2016-6652SQL injection vulnerability in Pivotal Spring Data JPA befor…
- CVE-2016-6653The MariaDB audit_plugin component in Pivotal Cloud Foundry …
- CVE-2016-6654Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-6655An issue was discovered in Cloud Foundry Foundation Cloud Fo…
- CVE-2016-6657An open redirect vulnerability has been detected with some P…
- CVE-2016-6658Applications in cf-release before 245 can be configured and …
- CVE-2016-6659Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x befor…
- CVE-2016-6660Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2016-6662Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x…
- CVE-2016-6663Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5…
Are you affected by CVE-2016-6656?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
