SQL injection in PostgreSQL - CVE-2018-10915
Published: August 11, 2018 / Updated: August 13, 2018
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL commands in web application database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker can send a specially crafted HTTP request to vulnerable script and execute arbitrary SQL commands in web application database.
Successful exploitation of the vulnerability may allow an attacker to gain administrative access to vulnerable web application.
Affected software
Amazon Linux AMI
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Opensuse
Fedora
Red Hat Virtualization Manager
CloudForms
postgresql (Alpine package)
postgresql
EMC Cloud Tiering Appliance
How to mitigate CVE-2018-10915
postgresql (Alpine package) - update to 9.6.10-r0
postgresql - addressed in versions 9.6.10-1.fc27, 10.5-1.fc28
EMC Cloud Tiering Appliance - update to 12.1.0.65
External References
Related Security Bulletins
- Multiple vulnerabilities in PostgreSQL
- Debian update for postgresql-9.6
- Red Hat update for PostgreSQL
- Red Hat update for PostgreSQL
- Red Hat update for PostgreSQL
- OpenSUSE Linux update for postgresql10
- Amazon Linux AMI update for postgresql96
- OpenSUSE Linux update for postgresql96
- Gentoo update for PostgreSQL
- Amazon Linux AMI update for postgresql96
- Amazon Linux AMI update for postgresql95
- Amazon Linux AMI update for postgresql93, postgresql94
- OpenSUSE Linux update for postgresql94
- Red Hat update for postgresql
- Amazon Linux AMI update for postgresql92
- Amazon Linux AMI update for postgresql93, postgresql94, postgresql95
- Red Hat update for postgresql
- OpenSUSE Linux update for postgresql96, postgresql10 and postgresql12
- SQL injection in postgresql (Alpine package)
- Multiple vulnerabilities in Dell EMC Cloud Tiering Appliance Family
- Fedora 27 update for postgresql
- Fedora 28 update for postgresql