CVE-2017-7546
critical · 9.8PostgreSQL versions before 9.2.22, 9.3.18, 9.4.13, 9.5.8 and 9.6.4 are vulnerable to incorrect authentication flaw allowing remote attackers to gain access to database accounts with an empty password.
9.8
CVSS
61.6%
EPSS (exploit prob.)
99th
EPSS percentile
2017-08-16
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-287
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| postgresql | postgresql | 9.2 |
| postgresql | postgresql | 9.2.1 |
| postgresql | postgresql | 9.2.2 |
| postgresql | postgresql | 9.2.3 |
| postgresql | postgresql | 9.2.4 |
| postgresql | postgresql | 9.2.5 |
| postgresql | postgresql | 9.2.6 |
| postgresql | postgresql | 9.2.7 |
| postgresql | postgresql | 9.2.8 |
| postgresql | postgresql | 9.2.9 |
| postgresql | postgresql | 9.2.10 |
| postgresql | postgresql | 9.2.11 |
| postgresql | postgresql | 9.2.12 |
| postgresql | postgresql | 9.2.13 |
| postgresql | postgresql | 9.2.14 |
| postgresql | postgresql | 9.2.15 |
| postgresql | postgresql | 9.2.16 |
| postgresql | postgresql | 9.2.17 |
| postgresql | postgresql | 9.2.18 |
| postgresql | postgresql | 9.2.19 |
| postgresql | postgresql | 9.2.20 |
| postgresql | postgresql | 9.2.21 |
| postgresql | postgresql | 9.3 |
| postgresql | postgresql | 9.3.1 |
| postgresql | postgresql | 9.3.2 |
| postgresql | postgresql | 9.3.3 |
| postgresql | postgresql | 9.3.4 |
| postgresql | postgresql | 9.3.5 |
| postgresql | postgresql | 9.3.6 |
| postgresql | postgresql | 9.3.7 |
| postgresql | postgresql | 9.3.8 |
| postgresql | postgresql | 9.3.9 |
| postgresql | postgresql | 9.3.10 |
| postgresql | postgresql | 9.3.11 |
| postgresql | postgresql | 9.3.12 |
| postgresql | postgresql | 9.3.13 |
| postgresql | postgresql | 9.3.14 |
| postgresql | postgresql | 9.3.15 |
| postgresql | postgresql | 9.3.16 |
| postgresql | postgresql | 9.3.17 |
Check a specific version with /api/v1/cve/match.
References
- http://www.debian.org/security/2017/dsa-3935
- http://www.debian.org/security/2017/dsa-3936
- http://www.securityfocus.com/bid/100278
- http://www.securitytracker.com/id/1039142
- https://access.redhat.com/errata/RHSA-2017:2677
- https://access.redhat.com/errata/RHSA-2017:2678
- https://access.redhat.com/errata/RHSA-2017:2728
- https://access.redhat.com/errata/RHSA-2017:2860
- https://security.gentoo.org/glsa/201710-06
- https://www.postgresql.org/about/news/1772/
- http://www.debian.org/security/2017/dsa-3935
- http://www.debian.org/security/2017/dsa-3936
- http://www.securityfocus.com/bid/100278
- http://www.securitytracker.com/id/1039142
- https://access.redhat.com/errata/RHSA-2017:2677
- https://access.redhat.com/errata/RHSA-2017:2678
- https://access.redhat.com/errata/RHSA-2017:2728
- https://access.redhat.com/errata/RHSA-2017:2860
- https://security.gentoo.org/glsa/201710-06
- https://www.postgresql.org/about/news/1772/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2017-7546