{"api_version":"1","generated_at":"2026-07-23T13:35:40+00:00","cve":"CVE-2009-3231","urls":{"html":"https://cve.report/CVE-2009-3231","api":"https://cve.report/api/cve/CVE-2009-3231.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2009-3231","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2009-3231"},"summary":{"title":"CVE-2009-3231","description":"The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.","state":"PUBLISHED","assigner":"mitre","published_at":"2009-09-17 10:30:01","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html","name":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[SECURITY] Fedora 10 Update: postgresql-8.3.8-1.fc10","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html","name":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2009:017","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/509917/100/0/threaded","name":"http://www.securityfocus.com/archive/1/509917/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=134124585221119&w=2","name":"http://marc.info/?l=bugtraq&m=134124585221119&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"'[security bulletin] HPSBMU02781 SSRT100617 rev.1 - HP Network Node Manager i (NNMi) for HP-UX, Linux' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36837","name":"http://secunia.com/advisories/36837","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Debian update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/36314","name":"http://www.securityfocus.com/bid/36314","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Third Party Advisory","VDB Entry"],"title":"PostgreSQL Multiple Security Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.ubuntu.com/usn/usn-834-1","name":"http://www.ubuntu.com/usn/usn-834-1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"USN-834-1: PostgreSQL vulnerabilities | Ubuntu","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html","name":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[SECURITY] Fedora 11 Update: postgresql-8.3.8-1.fc11","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.postgresql.org/docs/8.3/static/release-8-3-8.html","name":"http://www.postgresql.org/docs/8.3/static/release-8-3-8.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"PostgreSQL: Documentation: Manuals: PostgreSQL 8.3: Release 8.3.8","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36727","name":"http://secunia.com/advisories/36727","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"Fedora update for postgresql - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012","name":"http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.postgresql.org/support/security.html","name":"http://www.postgresql.org/support/security.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"PostgreSQL: \nSecurity Information","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/36800","name":"http://secunia.com/advisories/36800","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Security Advisory SA36800 - Ubuntu update for postgresql - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/36660","name":"http://secunia.com/advisories/36660","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Vendor Advisory"],"title":"PostgreSQL Multiple Vulnerabilities - Secunia Advisories - Vulnerability Information - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.us.debian.org/security/2009/dsa-1900","name":"http://www.us.debian.org/security/2009/dsa-1900","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"Debian -- Security Information -- DSA-1900-1 postgresql-7.4, postgresql-8.1, postgresql-8.3, postgresql-8.4","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=522084","name":"https://bugzilla.redhat.com/show_bug.cgi?id=522084","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Patch"],"title":"Bug 522084 – CVE-2009-3231 postgresql: LDAP authentication bypass when anonymous LDAP bind are allowed","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html","name":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[security-announce] SUSE Security Summary Report: SUSE-SR:2009:016","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2009-3231","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2009-3231","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2009","cve_id":"3231","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"postgresql","cpe5":"postgresql","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2009-3231","organization":"Red Hat","lastmodified":"2009-09-24","contributor":"Tomas Hoger","statementText":"Not vulnerable. This issue did not affect the versions of PostgreSQL as shipped with Red Hat Enterprise Linux 3, 4, or 5, as they do not support LDAP authentication, which was introduced upstream in version 8.2. This issue was addressed in Red Hat Application Stack v2 via https://rhn.redhat.com/errata/RHSA-2009-1461.html .","cve_year":"2009","cve_id":"3231","crc32":"ccbcd70c"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T06:22:23.182Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"FEDORA-2009-9474","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.postgresql.org/docs/8.3/static/release-8-3-8.html"},{"name":"36314","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/36314"},{"name":"HPSBMU02781","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=134124585221119&w=2"},{"name":"36837","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36837"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.postgresql.org/support/security.html"},{"name":"36660","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36660"},{"name":"20100307 rPSA-2010-0012-1 postgresql postgresql-contrib postgresql-server","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/509917/100/0/threaded"},{"name":"36800","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36800"},{"name":"DSA-1900","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.us.debian.org/security/2009/dsa-1900"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=522084"},{"name":"FEDORA-2009-9473","tags":["vendor-advisory","x_refsource_FEDORA","x_transferred"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html"},{"name":"SUSE-SR:2009:016","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html"},{"name":"36727","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/36727"},{"name":"SUSE-SR:2009:017","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html"},{"name":"USN-834-1","tags":["vendor-advisory","x_refsource_UBUNTU","x_transferred"],"url":"http://www.ubuntu.com/usn/usn-834-1"},{"name":"SSRT100617","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=134124585221119&w=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2009-09-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-10T18:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"FEDORA-2009-9474","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.postgresql.org/docs/8.3/static/release-8-3-8.html"},{"name":"36314","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/36314"},{"name":"HPSBMU02781","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=134124585221119&w=2"},{"name":"36837","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36837"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.postgresql.org/support/security.html"},{"name":"36660","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36660"},{"name":"20100307 rPSA-2010-0012-1 postgresql postgresql-contrib postgresql-server","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/509917/100/0/threaded"},{"name":"36800","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36800"},{"name":"DSA-1900","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.us.debian.org/security/2009/dsa-1900"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=522084"},{"name":"FEDORA-2009-9473","tags":["vendor-advisory","x_refsource_FEDORA"],"url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html"},{"name":"SUSE-SR:2009:016","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html"},{"name":"36727","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/36727"},{"name":"SUSE-SR:2009:017","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html"},{"name":"USN-834-1","tags":["vendor-advisory","x_refsource_UBUNTU"],"url":"http://www.ubuntu.com/usn/usn-834-1"},{"name":"SSRT100617","tags":["vendor-advisory","x_refsource_HP"],"url":"http://marc.info/?l=bugtraq&m=134124585221119&w=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2009-3231","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"FEDORA-2009-9474","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00307.html"},{"name":"http://www.postgresql.org/docs/8.3/static/release-8-3-8.html","refsource":"CONFIRM","url":"http://www.postgresql.org/docs/8.3/static/release-8-3-8.html"},{"name":"36314","refsource":"BID","url":"http://www.securityfocus.com/bid/36314"},{"name":"HPSBMU02781","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=134124585221119&w=2"},{"name":"36837","refsource":"SECUNIA","url":"http://secunia.com/advisories/36837"},{"name":"http://www.postgresql.org/support/security.html","refsource":"CONFIRM","url":"http://www.postgresql.org/support/security.html"},{"name":"36660","refsource":"SECUNIA","url":"http://secunia.com/advisories/36660"},{"name":"20100307 rPSA-2010-0012-1 postgresql postgresql-contrib postgresql-server","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/509917/100/0/threaded"},{"name":"36800","refsource":"SECUNIA","url":"http://secunia.com/advisories/36800"},{"name":"DSA-1900","refsource":"DEBIAN","url":"http://www.us.debian.org/security/2009/dsa-1900"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=522084","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=522084"},{"name":"FEDORA-2009-9473","refsource":"FEDORA","url":"https://www.redhat.com/archives/fedora-package-announce/2009-September/msg00305.html"},{"name":"SUSE-SR:2009:016","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00001.html"},{"name":"36727","refsource":"SECUNIA","url":"http://secunia.com/advisories/36727"},{"name":"SUSE-SR:2009:017","refsource":"SUSE","url":"http://lists.opensuse.org/opensuse-security-announce/2009-10/msg00004.html"},{"name":"USN-834-1","refsource":"UBUNTU","url":"http://www.ubuntu.com/usn/usn-834-1"},{"name":"SSRT100617","refsource":"HP","url":"http://marc.info/?l=bugtraq&m=134124585221119&w=2"},{"name":"http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012","refsource":"CONFIRM","url":"http://wiki.rpath.com/wiki/Advisories:rPSA-2010-0012"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2009-3231","datePublished":"2009-09-17T10:00:00.000Z","dateReserved":"2009-09-16T00:00:00.000Z","dateUpdated":"2024-08-07T06:22:23.182Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2009-09-17 10:30:01","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"8.2","versionEndExcluding":"8.2.14","matchCriteriaId":"8E2B520E-AB78-490D-87F0-1CEAB599D73E"},{"vulnerable":true,"criteria":"cpe:2.3:a:postgresql:postgresql:*:*:*:*:*:*:*:*","versionStartIncluding":"8.3","versionEndExcluding":"8.3.8","matchCriteriaId":"18915BE0-FFBE-4B74-B8F1-1E55DB6C06D3"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:opensuse:opensuse:*:*:*:*:*:*:*:*","versionStartIncluding":"10.3","versionEndIncluding":"11.1","matchCriteriaId":"FF141FBE-4CA5-4695-94A0-8BE1309D28CC"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise:10.0:sp2:*:*:*:*:*:*","matchCriteriaId":"6A3B50EE-F432-40BE-B422-698955A6058D"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise:11.0:-:*:*:*:*:*:*","matchCriteriaId":"1608E282-2E96-4447-848D-DBE915DB0EF9"},{"vulnerable":true,"criteria":"cpe:2.3:o:suse:linux_enterprise_server:9:*:*:*:*:*:*:*","matchCriteriaId":"4CD2D897-E321-4CED-92E0-11A98B52053C"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:10:*:*:*:*:*:*:*","matchCriteriaId":"7000D33B-F3C7-43E8-8FC7-9B97AADC3E12"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:11:*:*:*:*:*:*:*","matchCriteriaId":"B3BB5EDB-520B-4DEF-B06E-65CA13152824"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:6.06:*:*:*:*:*:*:*","matchCriteriaId":"454A5D17-B171-4F1F-9E0B-F18D1E5CA9FD"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.04:*:*:*:-:*:*:*","matchCriteriaId":"7EBFE35C-E243-43D1-883D-4398D71763CC"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:8.10:*:*:*:*:*:*:*","matchCriteriaId":"4747CC68-FAF4-482F-929A-9DA6C24CB663"},{"vulnerable":true,"criteria":"cpe:2.3:o:canonical:ubuntu_linux:9.04:*:*:*:*:*:*:*","matchCriteriaId":"A5D026D0-EF78-438D-BEDD-FC8571F3ACEB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2009","CveId":"3231","Ordinal":"1","Title":"CVE-2009-3231","CVE":"CVE-2009-3231","Year":"2009"},"notes":[{"CveYear":"2009","CveId":"3231","Ordinal":"1","NoteData":"The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.","Type":"Description","Title":"CVE-2009-3231"},{"CveYear":"2009","CveId":"3231","Ordinal":"2","NoteData":"2009-09-17","Type":"Other","Title":"Published"},{"CveYear":"2009","CveId":"3231","Ordinal":"3","NoteData":"2018-10-10","Type":"Other","Title":"Modified"}]}}}