Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-15099
Description:INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege.
Test IDs: 1.3.6.1.4.1.25623.1.0.812311   1.3.6.1.4.1.25623.1.0.704028   1.3.6.1.4.1.25623.1.0.812312  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-15099
BugTraq ID: 101781
http://www.securityfocus.com/bid/101781
Debian Security Information: DSA-4028 (Google Search)
https://www.debian.org/security/2017/dsa-4028
https://www.postgresql.org/support/security/
RedHat Security Advisories: RHSA-2018:2511
https://access.redhat.com/errata/RHSA-2018:2511
RedHat Security Advisories: RHSA-2018:2566
https://access.redhat.com/errata/RHSA-2018:2566
http://www.securitytracker.com/id/1039752




© 1998-2025 E-Soft Inc. All rights reserved.