Known vulnerabilities in postgresql-jdbc (Red Hat package)
Vendor:
Red Hat Inc.
Software:
postgresql-jdbc (Red Hat package)
Software CPE:
cpe:2.3:o:red_hat:postgresql-jdbc_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Website:
https://www.redhat.com/en
Total vulnerabilities:
13
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
42.2.3-7.el8_4.1
42.2.3-5.el8_6.1
42.2.28-1.el9_2.1
42.2.14-5.el8_8.1
42.2.28-1.el9_6.1
42.2.28-1.el9_4.1
42.7.1-7.el10_0.1
42.2.14-4.el8_10
42.2.28-2.el9_8.2
42.2.3-5.el8_6
42.2.14-5.el8_8
42.2.3-5.el8_2
42.2.28-1.el9_0
42.2.28-1.el9_2
42.2.28-1.el9_3
42.2.14-3.el8_9
42.2.14-2.el8
42.2.27-1.el9
42.2.14-2.el8ev
42.2.3-3.el8_1
9.2.1002-8.el7_8
8.4.704-4.el6_10
42.2.3-3.el8_0
42.2.3-3.el8_2
42.2.18-6.el9_1
42.2.14-1.el8ev
8.2.508-1jpp.el5s2
8.2.509-2jpp.el5s2
8.2.510-1jpp.el5s2
8.4.704-2.el6
8.4.701-8.el6
8.4.701-3.el6
Vulnerabilities (13)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU128414 - Allocation of Resources Without Limits or Throttling CVE-2026-42198 |
CWE-770 | Medium | 42.2.3-5.el8_6.1, 42.2.3-7.el8_4.1, 42.2.14-4.el8_10, 42.2.14-5.el8_8.1, 42.2.28-1.el9_2.1, 42.2.28-1.el9_4.1, 42.2.28-1.el9_6.1, 42.2.28-2.el9_8.2, 42.7.1-7.el10_0.1 | 28.04.2026 |
SB20260428236 SB2026052067 SB2026052092 and 23 more |
||
| #VU86983 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2024-1597 |
CWE-89 | High | 42.2.3-5.el8_2, 42.2.3-5.el8_6, 42.2.14-3.el8_9, 42.2.14-5.el8_8, 42.2.28-1.el9_0, 42.2.28-1.el9_2, 42.2.28-1.el9_3 | 04.03.2024 |
SB2024030405 SB2024030406 SB2024030427 and 47 more |
||
| #VU69545 - Incorrect Default Permissions CVE-2022-41946 |
CWE-276 | Low | 42.2.14-2.el8, 42.2.14-2.el8ev, 42.2.27-1.el9 | 23.11.2022 |
SB2022112335 SB2023010922 SB2023011025 and 42 more |
||
| #VU66747 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') CVE-2022-31197 |
CWE-89 | High | 42.2.18-6.el9_1 | 24.08.2022 |
SB2022082432 SB2022082543 SB2022090901 and 27 more |
||
| #VU65358 - Exposure of sensitive information to an unauthorized actor CVE-2022-31051 |
CWE-200 | Medium | 42.2.14-1.el8ev | 15.07.2022 |
SB2022071701 |
||
| #VU63709 - Incorrect Regular Expression CVE-2021-33623 |
CWE-185 | Medium | 42.2.14-1.el8ev | 26.05.2022 |
SB2022071701 SB2023040536 SB2023051544 and 2 more |
||
| #VU61760 - Incorrect Regular Expression CVE-2022-22950 |
CWE-185 | Medium | 42.2.14-1.el8ev | 31.03.2022 |
SB2022033110 SB2022060308 SB2022060324 and 25 more |
||
| #VU57967 - Improper input validation CVE-2021-3807 |
CWE-20 | Medium | 42.2.14-1.el8ev | 05.11.2021 |
SB2021110513 SB2021112603 SB2022042257 and 51 more |
||
| #VU54854 - Loop with Unreachable Exit Condition ('Infinite Loop') CVE-2021-35515 |
CWE-835 | Medium | 42.2.14-1.el8ev | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 23 more |
||
| #VU54853 - Resource exhaustion CVE-2021-36090 |
CWE-400 | Medium | 42.2.14-1.el8ev | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 70 more |
||
| #VU54852 - Resource exhaustion CVE-2021-35517 |
CWE-400 | Medium | 42.2.14-1.el8ev | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 33 more |
||
| #VU54851 - Resource exhaustion CVE-2021-35516 |
CWE-400 | Medium | 42.2.14-1.el8ev | 14.07.2021 |
SB2021071408 SB2021080809 SB2021100411 and 21 more |
||
| #VU41479 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2020-13692 |
CWE-611 | Medium | 8.4.704-4.el6_10, 9.2.1002-8.el7_8, 42.2.3-3.el8_0, 42.2.3-3.el8_1, 42.2.3-3.el8_2 | 10.08.2020 |
SB2020060439 SB2020081017 SB2020081018 and 13 more |