CVE-2023-41118
- EPSS 0.07%
- Veröffentlicht 12.12.2023 07:15:45
- Zuletzt bearbeitet 21.11.2024 08:20:37
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It may allow an authenticated user to bypass authorization requirements a...
CVE-2023-41119
- EPSS 0.08%
- Veröffentlicht 12.12.2023 07:15:45
- Zuletzt bearbeitet 21.11.2024 08:20:37
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the function _dbms_aq_move_to_exception_queue that may be use...
CVE-2023-41120
- EPSS 0.05%
- Veröffentlicht 12.12.2023 07:15:45
- Zuletzt bearbeitet 21.11.2024 08:20:38
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It permits an authenticated user to use DBMS_PROFILER to remove all accum...
CVE-2023-41116
- EPSS 0.06%
- Veröffentlicht 12.12.2023 07:15:44
- Zuletzt bearbeitet 21.11.2024 08:20:37
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to refresh any materialized view, regardl...
CVE-2023-41117
- EPSS 0.08%
- Veröffentlicht 12.12.2023 07:15:44
- Zuletzt bearbeitet 27.05.2025 15:15:30
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contain packages, standalone packages, and functions that run SECURITY...
CVE-2023-41114
- EPSS 0.08%
- Veröffentlicht 12.12.2023 07:15:43
- Zuletzt bearbeitet 21.11.2024 08:20:37
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the functions get_url_as_text and get_url_as_bytea that are p...
CVE-2023-41115
- EPSS 0.14%
- Veröffentlicht 12.12.2023 07:15:43
- Zuletzt bearbeitet 21.11.2024 08:20:37
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTL_ENCODE, an authenticated user can read any large object, r...
CVE-2023-41113
- EPSS 0.09%
- Veröffentlicht 12.12.2023 07:15:42
- Zuletzt bearbeitet 21.11.2024 08:20:36
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It allows an authenticated user to to obtain information about whether ce...
CVE-2023-31043
- EPSS 0.06%
- Veröffentlicht 23.04.2023 20:15:07
- Zuletzt bearbeitet 04.02.2025 17:15:15
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. Th...
CVE-2007-4639
- EPSS 15.73%
- Veröffentlicht 31.08.2007 23:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated users to cause a denial of service (daemon crash) and possibly execute arb...