CVE-2017-15099
Summary
| CVE | CVE-2017-15099 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-22 18:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | INSERT ... ON CONFLICT DO UPDATE commands in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, and 9.5.x before 9.5.10 disclose table contents that the invoker lacks privilege to read. These exploits affect only tables where the attacker lacks full read access but has both INSERT and UPDATE privileges. Exploits bypass row level security policies and lack of SELECT privilege. |
Risk And Classification
Primary CVSS: v3.0 6.5 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.271110000 probability, percentile 0.964320000 (date 2026-05-14)
Problem Types: CWE-200 | CWE-200 CWE-200
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:L/Au:S/C:P/I:N/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:S/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Application | Postgresql | Postgresql | 10.0 | All | All | All |
| Application | Postgresql | Postgresql | 9.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.5 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.7 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.8 | All | All | All |
| Application | Postgresql | Postgresql | 9.5.9 | All | All | All |
| Application | Postgresql | Postgresql | 9.6 | All | All | All |
| Application | Postgresql | Postgresql | 9.6.1 | All | All | All |
| Application | Postgresql | Postgresql | 9.6.2 | All | All | All |
| Application | Postgresql | Postgresql | 9.6.3 | All | All | All |
| Application | Postgresql | Postgresql | 9.6.4 | All | All | All |
| Application | Postgresql | Postgresql | 9.6.5 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat Inc. | Postgresql | affected 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| PostgreSQL: Security Information | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Issue Tracking, Vendor Advisory |
| PostgreSQL Bugs Let Remote Authenticated Users Bypass Access Controls and Obtain Potentially Sensitive Information and Let Local Users Modify Files on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| PostgreSQL: PostgreSQL 10.1, 9.6.6, 9.5.10, 9.4.15, 9.3.20, and 9.2.24 released! | af854a3a-2127-422b-91ae-364da2661108 | www.postgresql.org | Issue Tracking, Vendor Advisory |
| PostgreSQL Multipe Memory Corruption and Security Bypass Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Debian -- Security Information -- DSA-4028-1 postgresql-9.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.