Short Name |
DB:POSTGRESQL:SET-ROLE-BYPASS |
---|---|
Severity |
High |
Recommended |
No |
Category |
DB |
Keywords |
PostgreSQL Database SET ROLE Security Bypass |
Release Date |
2015/06/12 |
Update Number |
2504 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
A policy bypass vulnerability has been found in PostgreSQL database server. The vulnerability is due to a design weakness when granting a role without ADMIN OPTION. A remote attacker can exploit the vulnerability to cause a policy bypass allowing execution of a security-restricted operation or a SECURITY DEFINER function.