CVE Database
/

CVE-2017-15097

Back to search

CVE-2017-15097

Published: Jul 27, 2018

Modified: Aug 5, 2024

PUBLISHED

CVSS v3.0

6.5

MEDIUM

Description

Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine.

VendorProductVersions

Red Hat

postgresql init script

affected
all

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H

Attack Vector

Local

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

References

RHSA-2017:3402
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3403
vendor-advisory
x_refsource_REDHAT
RHSA-2017:3405
vendor-advisory
x_refsource_REDHAT
1039983
vdb-entry
x_refsource_SECTRACK
RHSA-2017:3404
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now