CVE-2016-2192
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
PostgreSQL PL/Java before 1.5.0 allows remote authenticated users to alter type mappings for types they do not own.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secalert@redhat.com — https://tada.github.io/pljava/releasenotes.html
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| pl\/java_project | pl\/java | {"endIncluding":"1.4.3"} | |
References
CWEs
CWE-269
Verify integrity in audit chain (admin only). AS-IS.