| Vulnerability Name: | CVE-2017-15097 (CCN-136153) | ||||||||||||||||||
| Assigned: | 2017-12-07 | ||||||||||||||||||
| Published: | 2017-12-07 | ||||||||||||||||||
| Updated: | 2023-02-12 | ||||||||||||||||||
| Summary: | Privilege escalation flaws were found in the Red Hat initialization scripts of PostgreSQL. An attacker with access to the postgres user account could use these flaws to obtain root access on the server machine. | ||||||||||||||||||
| CVSS v3 Severity: | 6.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 5.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.7 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||
| CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||||||||
| Vulnerability Type: | CWE-59 | ||||||||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2017-15097 Source: CCN Type: IBM Security Bulletin T1026733 (PowerKVM) Vulnerabilities in postgresql affect PowerKVM Source: CCN Type: IBM Security Bulletin 2016580 (Spectrum Protect Plus) PostgreSQL vulnerability affects IBM Spectrum Protect Plus (CVE-2017-15097) Source: secalert@redhat.com Type: Third Party Advisory, VDB Entry secalert@redhat.com Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com Source: secalert@redhat.com Type: Third Party Advisory secalert@redhat.com Source: CCN Type: Red Hat Bugzilla Bug 1508985 (CVE-2017-15097) CVE-2017-15097 postgresql: Start scripts permit database administrator to modify root-owned files Source: secalert@redhat.com Type: Issue Tracking, Third Party Advisory secalert@redhat.com Source: XF Type: UNKNOWN postgresql-cve201715097-priv-esc(136153) Source: CCN Type: PostgreSQL Web site PostgreSQL 10.1, 9.6.6, 9.5.10, 9.4.15, 9.3.20, and 9.2.24 released! Source: CCN Type: WhiteSource Vulnerability Database CVE-2017-15097 | ||||||||||||||||||
| Vulnerable Configuration: | Configuration RedHat 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||
| Oval Definitions | |||||||||||||||||||
| |||||||||||||||||||
| BACK | |||||||||||||||||||