6.8

CVE-2009-3231

The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.

Data is provided by the National Vulnerability Database (NVD)
PostgresqlPostgresql Version >= 8.2 < 8.2.14
PostgresqlPostgresql Version >= 8.3 < 8.3.8
OpensuseOpensuse Version >= 10.3 <= 11.1
SuseLinux Enterprise Version10.0 Updatesp2
SuseLinux Enterprise Version11.0 Update-
FedoraprojectFedora Version10
FedoraprojectFedora Version11
CanonicalUbuntu Linux Version6.06
CanonicalUbuntu Linux Version8.04 SwEdition-
CanonicalUbuntu Linux Version8.10
CanonicalUbuntu Linux Version9.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.96% 0.886
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.