CVE-2012-1618

high
Published 2012-10-06 · Modified 2023-11-08
CVSS v3
CVSS v2
7.5
VIR risk
7.5

Description

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-1618

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed0
debian debianbullseyefixed0
debian debianforkyfixed0
debian debiansidfixed0
debian debiantrixiefixed0

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.postgresql:postgresql<8.28.2

Application impact

VendorProductVersionsFixed
postgresql postgresqlpostgresql9.1
postgresql postgresqlpostgresql_jdbc_driver8.1

References

Verify integrity in audit chain (admin only). AS-IS.