Vulnerability Name:

CVE-2022-2625 (CCN-233970)

Assigned:2022-08-02
Published:2022-08-02
Updated:2022-12-02
Summary:A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a victim to use the object targeted in CREATE OR REPLACE or CREATE IF NOT EXISTS. Given all three prerequisites, this flaw allows an attacker to run arbitrary code as the victim role, which may be a superuser.
CVSS v3 Severity:8.0 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H)
7.0 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.1 High (REDHAT CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
6.2 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.1 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-915
CWE-1321
CWE-915
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2022-2625

Source: CCN
Type: Red Hat Bugzilla - Bug 2113825
CVE-2022-2625 postgresql: Extension scripts replace objects not belonging to the extension.

Source: secalert@redhat.com
Type: Issue Tracking, Third Party Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
postgresql-cve20222625-code-exec(233970)

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: IBM Security Bulletin 6842221 (Sterling Connect:Direct Web Services)
IBM Sterling Connect:Direct Web Services is vulnerable to remote authenticated attacker to execute arbitrary code on the system due to PostgreSQL (CVE-2022-2625)

Source: CCN
Type: IBM Security Bulletin 6845948 (Spectrum Copy Data Management)
Vulnerabilities in PostgreSQL, Open JDK, and Jettison may affect IBM Spectrum Copy Data Management

Source: CCN
Type: IBM Security Bulletin 6846157 (Data Risk Manager)
IBM Data Risk Manager is affected by multiple vulnerabilities including remote code execution in Apache Commons Text 1.9

Source: CCN
Type: IBM Security Bulletin 6955057 (Security QRadar SIEM)
IBM QRadar SIEM includes multiple components with known vulnerabilities

Source: CCN
Type: IBM Security Bulletin 6967285 (Spectrum Protect Plus Server)
Vulnerabilities in PostgreSQL may affect IBM Spectrum Protect Plus (CVE-2022-2625, CVE-2022-1552, CVE-2021-3677)

Source: CCN
Type: PostgreSQL Web site
PostgreSQL 14.5, 13.8, 12.12, 11.17, 10.22, and 15 Beta 3 Released!

Source: secalert@redhat.com
Type: Release Notes, Vendor Advisory
secalert@redhat.com

Vulnerable Configuration:Configuration RedHat 1:
  • cpe:/a:redhat:enterprise_linux:8:*:*:*:*:*:*:*
  • Configuration RedHat 2:
  • cpe:/a:redhat:enterprise_linux:8::appstream:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:ibm:qradar_security_information_and_event_manager:7.4:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8089
    P
    postgresql14-14.8-150200.5.26.1 on GA media (Moderate)
    2023-06-12
    oval:com.redhat.rhsa:def:20231576
    P
    RHSA-2023:1576: postgresql:13 security update (Moderate)
    2023-04-04
    oval:com.redhat.rhsa:def:20230113
    P
    RHSA-2023:0113: postgresql:10 security update (Moderate)
    2023-01-12
    oval:com.redhat.rhsa:def:20227128
    P
    RHSA-2022:7128: postgresql:12 security update (Moderate)
    2022-10-25
    oval:org.opensuse.security:def:721
    P
    Security update for postgresql13 (Important)
    2022-09-01
    oval:org.opensuse.security:def:722
    P
    Security update for postgresql12 (Important)
    2022-09-01
    oval:org.opensuse.security:def:723
    P
    Security update for postgresql14 (Important)
    2022-09-01
    oval:org.opensuse.security:def:5302
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119476
    P
    Security update for postgresql10 (Important)
    2022-08-31
    oval:org.opensuse.security:def:125764
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:127325
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119661
    P
    Security update for postgresql10 (Important)
    2022-08-31
    oval:org.opensuse.security:def:118799
    P
    Security update for postgresql10 (Important)
    2022-08-31
    oval:org.opensuse.security:def:118989
    P
    Security update for postgresql10 (Important)
    2022-08-31
    oval:org.opensuse.security:def:126928
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:119294
    P
    Security update for postgresql10 (Important)
    2022-08-31
    oval:org.opensuse.security:def:6110
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-31
    oval:org.opensuse.security:def:716
    P
    Security update for postgresql10 (Important)
    2022-08-31
    oval:org.opensuse.security:def:126953
    P
    Security update for postgresql10 (Important)
    2022-08-26
    oval:org.opensuse.security:def:6150
    P
    Security update for postgresql13 (Important)
    2022-08-26
    oval:org.opensuse.security:def:5334
    P
    Security update for postgresql13 (Important)
    2022-08-26
    oval:org.opensuse.security:def:6151
    P
    Security update for postgresql10 (Important)
    2022-08-26
    oval:org.opensuse.security:def:125790
    P
    Security update for postgresql10 (Important)
    2022-08-26
    oval:org.opensuse.security:def:5335
    P
    Security update for postgresql10 (Important)
    2022-08-26
    oval:org.opensuse.security:def:127351
    P
    Security update for postgresql10 (Important)
    2022-08-26
    oval:org.opensuse.security:def:119734
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-19
    oval:org.opensuse.security:def:119722
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-19
    oval:org.opensuse.security:def:118775
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-19
    oval:org.opensuse.security:def:118965
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-19
    oval:org.opensuse.security:def:119270
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-19
    oval:org.opensuse.security:def:119821
    P
    Security update for postgresql12 (Important) (in QA)
    2022-08-19
    oval:org.opensuse.security:def:119720
    P
    Security update for postgresql13 (Important) (in QA)
    2022-08-18
    oval:org.opensuse.security:def:118772
    P
    Security update for postgresql13 (Important) (in QA)
    2022-08-18
    oval:org.opensuse.security:def:118962
    P
    Security update for postgresql13 (Important) (in QA)
    2022-08-18
    oval:org.opensuse.security:def:119267
    P
    Security update for postgresql13 (Important) (in QA)
    2022-08-18
    oval:org.opensuse.security:def:119819
    P
    Security update for postgresql13 (Important) (in QA)
    2022-08-18
    oval:org.opensuse.security:def:119732
    P
    Security update for postgresql13 (Important) (in QA)
    2022-08-18
    oval:org.opensuse.security:def:119262
    P
    Security update for postgresql14 (Important) (in QA)
    2022-08-16
    oval:org.opensuse.security:def:119818
    P
    Security update for postgresql14 (Important) (in QA)
    2022-08-16
    oval:org.opensuse.security:def:119731
    P
    Security update for postgresql14 (Important) (in QA)
    2022-08-16
    oval:org.opensuse.security:def:119719
    P
    Security update for postgresql14 (Important) (in QA)
    2022-08-16
    oval:org.opensuse.security:def:118767
    P
    Security update for postgresql14 (Important) (in QA)
    2022-08-16
    oval:org.opensuse.security:def:118957
    P
    Security update for postgresql14 (Important) (in QA)
    2022-08-16
    BACK
    ibm qradar security information and event manager 7.4 -